Legal

Data Processing Agreement

Effective Date: February 2026

Document Version: 2.0

Preamble

This Data Processing Agreement ("DPA") is entered into by and between the entity that has executed the Terms of Service or a separate subscription agreement with Rymeda, Inc. (the "Controller" or "Business") and Rymeda, Inc., a Delaware corporation with its principal place of business in California (the "Processor" or "Service Provider"), collectively referred to as the "Parties."

This DPA forms part of and supplements the Terms of Service. It governs the processing of personal data by the Processor on behalf of the Controller and applies in addition to the Privacy Policy. Where personal data includes Protected Health Information ("PHI"), the Business Associate Agreement applies concurrently. In the event of conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data processing matters.

This DPA is designed to satisfy the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK Data Protection Act 2018/UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq.) ("CCPA/CPRA"), and other applicable data protection laws.

1. Definitions

In addition to terms defined elsewhere in this DPA, the following definitions apply:

1.1 "Personal Data"

Any information relating to an identified or identifiable natural person ("Data Subject"), as defined in GDPR Article 4(1). Under CCPA/CPRA, this corresponds to "personal information" as defined in Cal. Civ. Code §1798.140(v).

1.2 "Controller" / "Business"

The entity that determines the purposes and means of the processing of Personal Data (GDPR Article 4(7)). Under CCPA/CPRA, the "Business" as defined in Cal. Civ. Code §1798.140(d). This is the customer that has entered into a service agreement with Rymeda, Inc.

1.3 "Processor" / "Service Provider"

Rymeda, Inc., which processes Personal Data on behalf of the Controller (GDPR Article 4(8)). Under CCPA/CPRA, a "Service Provider" as defined in Cal. Civ. Code §1798.140(ag).

1.4 "Sub-processor"

Any third party engaged by the Processor to process Personal Data on behalf of the Controller, as contemplated by GDPR Article 28(2) and (4). A current list is maintained at the Subprocessor List.

1.5 "Data Subject" / "Consumer"

An identified or identifiable natural person whose Personal Data is processed (GDPR Article 4(1)). Under CCPA/CPRA, a "Consumer" as defined in Cal. Civ. Code §1798.140(i).

1.6 "Processing"

Any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction (GDPR Article 4(2)).

1.7 "Standard Contractual Clauses" or "SCCs"

The standard contractual clauses for the transfer of personal data to third countries pursuant to GDPR Article 46(2)(c), as set out in the European Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor).

1.8 "Sensitive Personal Data" / "Special Categories"

Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation (GDPR Article 9). Under CCPA/CPRA, "sensitive personal information" as defined in Cal. Civ. Code §1798.140(ae). On the Rymeda platform, this includes health data (PHI), biometric data (voice recordings), and precise geolocation.

2. Subject Matter and Duration

2.1 Subject Matter

The subject matter of this DPA is the Processor's provision of healthcare SaaS services, including clinical documentation, practice management, billing and claims, AI-assisted charting and transcription, marketplace, secure messaging, and related services as described in the Terms of Service.

2.2 Duration

Processing shall continue for the duration of the Terms of Service or subscription agreement, plus any retention period required by applicable law (including the six (6)-year HIPAA minimum retention period under 45 CFR §164.530(j) where applicable).

2.3 Nature and Purpose of Processing

The Processor processes Personal Data for the following purposes:

  • Platform operation: user authentication, authorization, session management, and role-based access control
  • Clinical documentation: patient records, clinical charts, SOAP notes, treatment plans, and care coordination
  • AI-assisted workflows: voice recording transcription (OpenAI Whisper), AI-generated clinical notes (OpenAI, Google Gemini), clinical decision support (ORIS AI), and task prioritization
  • Billing and payment: invoice creation with CPT codes, insurance claims processing with ICD-10/CPT codes, payment processing via Stripe
  • Provider verification: NPI/NPPES validation, license verification, DEA verification, and credential management
  • Marketplace operations: product listings, cart management, order fulfillment, vendor management, and reviews
  • Communication: secure messaging between providers and patients, transactional email notifications via SendGrid
  • Security and compliance: audit logging, access monitoring, incident detection, and compliance automation
  • Analytics: privacy-focused website analytics via Plausible (cookie-free, no PII)

3. Data Types and Data Subject Categories

3.1 Categories of Data Subjects

CategoryDescription
PatientsIndividuals whose health information is created, maintained, and managed by Covered Entity's authorized workforce through the platform
Healthcare ProvidersLicensed clinicians (physicians, NPs, PAs, RNs, therapists) who use the platform to deliver care and document clinical encounters
Staff MembersNon-clinical personnel (billers, front desk, org admins, owners) who manage practice operations through the platform
Social ProvidersWellness and community creators using social provider features (go live, monetization, communities, marketplace selling)
Marketplace UsersVendors and customers who participate in the Rymeda marketplace for healthcare products

3.2 Types of Personal Data Processed

CategorySpecific Data ElementsSpecial Category
Identity DataFirst name, last name, date of birth, gender, user ID (UUID)No
Contact DataEmail address, phone number, postal address (street, city, state, ZIP), emergency contact (name, relationship, phone)No
Health / Patient DataProblems (with ICD-10 codes), medications, allergies, vital signs (temperature, BP, HR, RR, O2 sat, weight, height), lab results, treatment plans, clinical notes (SOAP, progress, intake, discharge), appointment recordsYes — Health data (Art. 9 GDPR)
Biometric DataVoice recordings of clinical encounters (audio files in WebM, MP4, MPEG, WAV, OGG formats), voiceprints derived from transcription processingYes — Biometric data (Art. 9 GDPR)
AI-Generated DataAI transcriptions, AI SOAP notes, suggested ICD-10 codes with confidence scores, visit summaries, suggested diagnoses, follow-up recommendations, model version identifiersYes — Derived health data
Professional / Credential DataNPI number, NPPES registry data, clinical role, license information, DEA number, specialty, verification status, organization affiliationNo
Financial / Billing DataInsurance information (provider name, plan, member ID, group number), invoices with CPT codes, claims with diagnosis/procedure codes, payment method (via Stripe — Rymeda does not store card numbers), subscription tierNo
Communication DataSecure messages (content, attachments, priority, read receipts), email addresses for notificationsPotentially — if containing health data
Technical / Device DataIP address, browser type, device identifiers, session tokens, API access logsNo
Marketplace DataOrder history, product reviews (1-5 stars with text), vendor profiles (business name, business type, rating), shipping addressesNo

4. Controller Obligations

The Controller warrants and agrees that:

  • It has a valid legal basis for the processing of Personal Data under applicable data protection law (GDPR Article 6, and where applicable, Article 9 for special categories).
  • It has provided appropriate notice to Data Subjects regarding the processing of their Personal Data by the Processor, including the use of AI-assisted clinical documentation features.
  • It has obtained any required consents from Data Subjects, including explicit consent for the processing of special categories of Personal Data (health data, biometric data) where required by GDPR Article 9(2)(a) or applicable law.
  • It has obtained separate voice recording consent in compliance with California Penal Code §632 (two-party consent) and telehealth consent in compliance with California Business & Professions Code §2290.5, where applicable.
  • Its processing instructions to the Processor comply with applicable data protection law. The Controller shall immediately inform the Processor if it becomes aware that an instruction infringes applicable law.
  • It is responsible for configuring appropriate role-based access controls within the platform, including assigning correct clinical roles to staff members and maintaining accurate care team relationships.

5. Processor Obligations

In accordance with GDPR Article 28(3), the Processor agrees to:

5.1 Documented Instructions

Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by Union or Member State law to which the Processor is subject. In such case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such notice on grounds of public interest. The Terms of Service and this DPA constitute the Controller's documented instructions.

5.2 Confidentiality

Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b)). All Rymeda workforce members are bound by confidentiality agreements and undergo HIPAA security training.

5.3 Security Measures

Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by GDPR Article 32. Specific measures are detailed in Section 8 of this DPA.

5.4 Sub-processor Engagement

Not engage another processor (Sub-processor) without prior specific or general written authorization of the Controller, as detailed in Section 6 of this DPA (Article 28(2)).

5.5 Data Subject Rights Assistance

Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights (Article 28(3)(e)). Specific rights are detailed in Section 9 of this DPA.

5.6 Compliance Assistance

Assist the Controller in ensuring compliance with the obligations under GDPR Articles 32 to 36, taking into account the nature of processing and the information available to the Processor. This includes assistance with:

  • Security of processing (Article 32)
  • Notification of personal data breaches to supervisory authorities (Article 33)
  • Communication of personal data breaches to Data Subjects (Article 34)
  • Data Protection Impact Assessments (Article 35) — see Section 10
  • Prior consultation with supervisory authorities (Article 36)

5.7 Data Return or Deletion

At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage (Article 28(3)(g)). Details in Section 12.

5.8 Audit and Inspection

Make available to the Controller all information necessary to demonstrate compliance with Article 28 obligations and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (Article 28(3)(h)). Details in Section 11.

5.9 Notification of Infringement

Immediately inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions (Article 28(3), last sentence).

6. Sub-processor Management

6.1 General Authorization

The Controller provides general written authorization for the Processor to engage Sub-processors listed in Section 6.3 below and on the Subprocessor List as of the effective date of this DPA, in accordance with GDPR Article 28(2).

6.2 Notification and Objection Rights

The Processor shall provide the Controller with thirty (30) days' advance written notice before adding or replacing a Sub-processor, specifying: (a) the identity of the Sub-processor; (b) the nature of services; (c) the categories of Personal Data processed; and (d) the location of processing.

The Controller may object to a new Sub-processor within fifteen (15) days of notification by providing written objection to legal@rymeda.com. If the Controller raises a reasonable objection, the Processor shall: (a) make commercially reasonable efforts to provide an alternative; or (b) if no alternative is available, permit the Controller to terminate the affected services without penalty, with a pro-rata refund of prepaid fees.

6.3 Current Sub-processors

Sub-processorPurposeData ProcessedLocation
Amazon Web Services, Inc.Cloud infrastructure, compute, S3 storage, KMS, networkingAll Personal Data including ePHI, voice audio files, database hostingUS-East-1
MongoDB, Inc.Database-as-a-service (Atlas)Patient records, clinical charts, notes, staff records, audit logs, all structured dataUS (AWS)
Stripe, Inc.Payment processing (subscriptions, marketplace)Billing data, payment card information (PCI DSS compliant), no clinical dataUnited States
OpenAI, Inc.Voice transcription (Whisper), AI clinical note generationVoice audio recordings, clinical note contentUnited States
Google LLC (Gemini)AI clinical note generation, decision supportClinical note content, de-identified clinical contextUnited States
ORISClinical AI assistant, task generation, daily runbooksClinical context for decision supportUnited States
Twilio SendGridTransactional email deliveryEmail addresses, notification content (minimized via redaction pipeline)United States
Plausible AnalyticsPrivacy-focused website analyticsNo Personal Data — cookie-free, no PII, no cross-site trackingEuropean Union

6.4 Sub-processor Agreements

The Processor shall impose on each Sub-processor, by way of contract, data protection obligations no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing meets the requirements of applicable data protection law. The Processor shall remain fully liable to the Controller for the performance of each Sub-processor's obligations (GDPR Article 28(4)).

7. International Data Transfers

7.1 Transfer Mechanism

The Processor's primary infrastructure is located in AWS US-East-1 (Northern Virginia, United States). For transfers of Personal Data from the European Economic Area ("EEA"), United Kingdom, or Switzerland to the United States, the Parties agree that the Standard Contractual Clauses ("SCCs") adopted by the European Commission Implementing Decision (EU) 2021/914 shall apply as follows:

  • Module Two (Controller to Processor): Where the Controller is established in the EEA/UK and the Processor processes Personal Data in the United States.
  • The SCCs are incorporated by reference and form an integral part of this DPA. In the event of conflict between this DPA and the SCCs, the SCCs shall prevail.
  • For UK transfers, the UK International Data Transfer Addendum to the EU SCCs (as issued by the UK Information Commissioner) applies.
  • For Swiss transfers, the SCCs apply with the modifications required by the Swiss Federal Act on Data Protection ("FADP").

7.2 Transfer Impact Assessment

The Processor has conducted a Transfer Impact Assessment ("TIA") and determined that the supplementary measures described in Section 8 (Security Measures) provide an essentially equivalent level of protection for Personal Data transferred to the United States. These supplementary measures include AES-256 encryption, per-tenant KMS keys, tenant isolation, and access controls that prevent unauthorized government access.

7.3 Sub-processor Transfers

All Sub-processors listed in Section 6.3 that process Personal Data outside the EEA are bound by Standard Contractual Clauses or an equivalent transfer mechanism. Plausible Analytics is hosted in the EU and does not transfer Personal Data internationally.

8. Security Measures

The Processor implements the following technical and organizational measures pursuant to GDPR Article 32:

MeasureImplementation
Encryption at RestAES-256 encryption with per-tenant AWS KMS keys for all stored Personal Data
Encryption in TransitTLS 1.3 for all data in transit; HTTPS-only API endpoints; encrypted WebSocket connections
Access ControlRole-based access control with 9-role clinical permission matrix; principle of least privilege; UUID-based user identification; JWT authentication
Audit LoggingImmutable, append-only audit trails recording user ID, clinical role, action, entity type/ID, timestamp, and metadata; 6-year retention; admin-only access
Tenant IsolationComplete data separation between tenants with isolated compute, storage, and network boundaries; zero cross-tenant data visibility
PHI Redaction PipelineAutomated multi-stage ML-powered entity recognition for PHI detection and redaction before data reaches external processing layers
Network SecurityVPC isolation, WAF protection, DDoS mitigation, API Gateway rate limiting
Vulnerability ManagementContinuous vulnerability scanning, automated patching, annual penetration testing
Incident ResponseDocumented Incident Response Plan with defined escalation paths and notification timelines
Personnel SecurityConfidentiality agreements, background checks, HIPAA security training, immediate access revocation upon termination

For complete details, see the Security page and Information Security Policy.

9. Data Subject Rights Assistance

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests under applicable law:

9.1 GDPR Rights (Articles 15-22)

RightArticleProcessor Assistance
Right of AccessArt. 15Provide data export in machine-readable format within 30 days
Right to RectificationArt. 16Update Personal Data via platform or API upon Controller instruction
Right to ErasureArt. 17Delete Personal Data upon Controller instruction (subject to legal retention requirements)
Right to RestrictionArt. 18Restrict processing of specific data upon Controller instruction
Right to Data PortabilityArt. 20Export data in structured, commonly used, machine-readable format (JSON/CSV)
Right to ObjectArt. 21Cease processing upon Controller instruction where based on legitimate interest
Automated Decision-MakingArt. 22All AI-generated clinical content requires human review and provider signature; no solely automated decisions with legal effect

9.2 CCPA/CPRA Rights

RightCitation
Right to Know / AccessCal. Civ. Code §1798.100
Right to DeleteCal. Civ. Code §1798.105
Right to CorrectCal. Civ. Code §1798.106
Right to Data PortabilityCal. Civ. Code §1798.100(d)
Right to Opt Out of Sale/SharingCal. Civ. Code §1798.120
Right to Limit Use of Sensitive PICal. Civ. Code §1798.121
Right to Non-DiscriminationCal. Civ. Code §1798.125

For data that also constitutes PHI, HIPAA rights (45 CFR §§164.524-528) apply and may differ from CCPA rights. The Business Associate Agreement governs PHI-specific access rights.

10. Data Protection Impact Assessment Assistance

Where the Controller is required to carry out a Data Protection Impact Assessment ("DPIA") under GDPR Article 35, the Processor shall provide reasonable assistance, taking into account the nature of the processing and the information available to the Processor. This assistance may include:

  • A description of the processing operations and purposes
  • Information about the technical and organizational security measures implemented (Section 8)
  • Information about Sub-processors and international transfers (Sections 6 and 7)
  • Information about the AI systems used and their risk classification under the EU AI Act
  • Records of processing activities maintained by the Processor under GDPR Article 30(2)
  • Assessment of necessity, proportionality, and risks to Data Subjects

The Processor acknowledges that its AI-assisted clinical documentation features (voice transcription, AI-generated SOAP notes, clinical decision support) may constitute "high-risk AI systems" under the EU AI Act (Regulation (EU) 2024/1689), particularly where they involve processing of health data and may influence clinical decisions. The Processor cooperates with Controllers in meeting EU AI Act obligations.

11. Audit Rights

11.1 Information Availability

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in GDPR Article 28 and this DPA.

11.2 Third-Party Audits

The Processor maintains annual SOC 2 Type II audit reports conducted by an independent third-party auditor. The Processor shall make the most recent SOC 2 report available to the Controller upon written request, subject to the Processor's reasonable confidentiality requirements.

11.3 On-Site Audits

The Controller (or an independent third-party auditor bound by confidentiality obligations) may conduct an on-site audit of the Processor's processing activities, subject to the following conditions:

  • No more than one (1) audit per calendar year, unless a data breach or material non-compliance is suspected
  • At least thirty (30) days' advance written notice
  • Conducted during normal business hours
  • Shall not unreasonably disrupt the Processor's operations or compromise the security of other customers' data
  • The auditor shall be bound by confidentiality obligations no less protective than those in this DPA
  • The Controller shall bear the costs of any audit, except where the audit reveals material non-compliance by the Processor

12. Data Return and Deletion

12.1 Post-Termination Obligations

Upon termination of the Terms of Service or this DPA, the Processor shall, at the Controller's election:

  • Return: Provide the Controller with all Personal Data in a structured, commonly used, machine-readable format (JSON or CSV) within thirty (30) days of the Controller's written request
  • Delete: Securely delete all Personal Data within thirty (30) days, using cryptographic erasure for encrypted data and NIST SP 800-88 compliant methods for unencrypted data

12.2 Certification of Deletion

Upon completion of deletion, the Processor shall provide written certification confirming the deletion of all Personal Data, specifying: (a) the date of deletion; (b) the categories of data deleted; (c) the methods of destruction used; and (d) identification of the authorized person who oversaw the deletion.

12.3 Retention Exceptions

The Processor may retain Personal Data beyond the termination period where required by applicable law, including:

  • PHI retention for six (6) years per 45 CFR §164.530(j)
  • Clinical records per California retention requirements (7 years for adults, until age 19 for minors)
  • Financial records per tax and accounting regulations (7 years)
  • Audit logs per HIPAA requirements (6 years)
  • Data subject to a legal hold for pending or anticipated litigation

Where retention is required, the Processor shall: (a) limit processing to the purpose requiring retention; (b) maintain all security measures; and (c) delete the data upon expiration of the retention period.

13. Personal Data Breach Notification

13.1 Notification Timeline

The Processor shall notify the Controller without undue delay, and in no event later than seventy-two (72) hours, after becoming aware of a Personal Data breach, in accordance with GDPR Article 33(2). This timeline is in addition to (and may differ from) the breach notification obligations under the BAA (30 calendar days for HIPAA breaches) and the Breach Notification Policy.

13.2 Notification Content

The notification shall include, to the extent available:

  • The nature of the Personal Data breach, including the categories and approximate number of Data Subjects and records concerned (Article 33(3)(a))
  • The name and contact details of the Processor's data protection officer or equivalent contact point (Article 33(3)(b))
  • The likely consequences of the breach (Article 33(3)(c))
  • The measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects (Article 33(3)(d))

13.3 California-Specific Requirements

For breaches affecting California residents, the Processor additionally complies with Cal. Civ. Code §1798.82 (SB 446), including notification within thirty (30) days and notification to the California Attorney General when more than 500 residents are affected. For breaches involving medical information, the Processor complies with CMIA (Cal. Civ. Code §56.36) and Cal. Health & Safety Code §1280.15.

14. CCPA/CPRA Service Provider Addendum

For Personal Data subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq.), the Processor certifies and agrees that it:

14.1 Service Provider Status

Qualifies as a "Service Provider" under Cal. Civ. Code §1798.140(ag) and processes personal information on behalf of the Business solely for the business purposes specified in the Terms of Service and this DPA.

14.2 No Sale or Sharing

Does not "sell" personal information as defined in Cal. Civ. Code §1798.140(ad), and does not "share" personal information for cross-context behavioral advertising as defined in Cal. Civ. Code §1798.140(ah).

14.3 Purpose Limitation

Does not retain, use, or disclose personal information for any purpose other than the business purposes specified in this DPA, including any commercial purpose other than providing the services described herein.

14.4 No Combining

Does not combine personal information received from the Business with personal information received from other persons or collected from its own interactions with consumers, except as permitted under Cal. Civ. Code §1798.140(ag)(1)(A)-(E).

14.5 Compliance Verification

Grants the Business the right to take reasonable and appropriate steps to ensure compliance, including ongoing manual reviews and automated scans, and to stop and remediate unauthorized use of personal information.

14.6 Notification of Inability to Comply

Shall notify the Business if it determines that it can no longer meet its obligations under the CCPA/CPRA as a Service Provider.

HIPAA Exemption: Personal information that constitutes PHI governed by HIPAA is exempt from CCPA/CPRA requirements per Cal. Civ. Code §1798.145(c)(1)(A). The BAA governs all PHI processing.

15. Liability

15.1 Allocation of Liability

Each Party shall be liable for damages caused by processing which infringes applicable data protection law, in accordance with GDPR Article 82. The Processor shall be liable for damage caused by processing only where it has not complied with obligations specifically directed to processors, or where it has acted outside of or contrary to lawful instructions of the Controller.

15.2 Limitation

The total aggregate liability of the Processor under or in connection with this DPA shall be subject to the limitation of liability provisions in the Terms of Service, except to the extent such limitation is prohibited by applicable data protection law.

15.3 Indemnification

Each Party shall indemnify and hold harmless the other Party from and against any claims, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising from the indemnifying Party's breach of this DPA or violation of applicable data protection law.

16. General Provisions

16.1 Governing Law

This DPA shall be governed by the laws of the State of Delaware, without regard to conflict of laws principles. For matters subject to the GDPR, the provisions of the GDPR shall apply. For matters involving PHI, federal HIPAA regulations govern to the extent applicable. The CCPA/CPRA applies to all processing of personal information of California residents, subject to the HIPAA exemption in Cal. Civ. Code §1798.145(c)(1)(A).

16.2 Amendment

This DPA may be amended by the Processor upon thirty (30) days' written notice to the Controller to comply with changes to applicable data protection law. Material amendments to the processing scope require the Controller's prior written consent.

16.3 Severability

If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

16.4 Precedence

In the event of conflict: (a) the SCCs shall prevail over this DPA with respect to international transfers; (b) this DPA shall prevail over the Terms of Service with respect to data processing; (c) the BAA shall prevail over this DPA with respect to PHI.

16.5 Survival

Sections 9 (Data Subject Rights), 11 (Audit Rights), 12 (Data Return and Deletion), 13 (Breach Notification), 14 (CCPA/CPRA Addendum), and 15 (Liability) shall survive termination of this DPA.

17. Contact Information

For questions regarding this DPA, data processing inquiries, or to exercise any rights:

Privacy Officer / DPO Contact

legal@rymeda.com

Data subject requests, DPIA assistance, privacy inquiries

Legal Department

legal@rymeda.com

DPA amendments, Sub-processor objections, audit requests

Compliance Office

legal@rymeda.com

Breach notifications, compliance certifications, regulatory inquiries

Sub-processor Updates

legal@rymeda.com

Subscribe to Sub-processor change notifications

Related Policies