HealthEase now runs whole hospitals, not just the front desk. Read more →

Legal

Data Processing Agreement

Last updated: 26 July 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between Vanta (Private) Limited ("Vanta", "Processor"), a company incorporated in Pakistan, and the customer identified in the Order Form or online registration (the "Customer", "Controller") governing the Customer's use of the HealthEase service (the "Agreement", meaning the HealthEase Subscription Agreement together with any signed Order Form).

We may update this DPA from time to time as described below in the security-measures versioning and sub-processor change provisions; material changes are notified to the Customer, and the "Last updated" date above reflects the current version. Questions about this DPA may be sent to info@healthease.app.

1. Definitions

1.1 "Applicable Data Protection Law" means all laws applying to the Processing of Personal Data under this DPA, including (where applicable to a party) Pakistani data-protection law as enacted, the EU GDPR, the UK GDPR, the Singapore PDPA 2012, and equivalent laws elsewhere. 1.2 "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor", and "Personal Data Breach" have the meanings given by Applicable Data Protection Law; where terms differ across laws, the meaning most protective of Data Subjects applies. 1.3 "Customer Data" means Personal Data the Customer (or its users, or patients) submits to the Service and that Vanta Processes on the Customer's behalf — including patient health data. 1.4 "Service" means the HealthEase clinic and hospital management software (hosted service and Windows/Android/iOS applications).

2. Roles and scope

2.1 For Customer Data, the Customer is the Controller and Vanta is the Processor. Vanta Processes Customer Data only on the Customer's behalf and documented instructions. 2.2 Vanta acts as an independent controller only for its own account, billing, and service-administration data, which is outside this DPA. 2.3 This DPA applies for as long as Vanta Processes Customer Data, and prevails over conflicting terms of the Agreement with respect to the Processing of Personal Data.

3. Details of Processing

The subject matter, duration, nature and purpose of the Processing, and the categories of Personal Data and Data Subjects, are set out in the details-of-processing annex at the end of this DPA.

4. Processor obligations

Vanta shall:

4.1 Instructions. Process Customer Data only on the Customer's documented instructions — the Agreement, this DPA, and the Customer's configuration and use of the Service constitute those instructions — unless required otherwise by law that applies to Vanta, in which case Vanta will inform the Customer of that legal requirement before Processing unless the law prohibits it. Vanta will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. 4.2 Confidentiality. Ensure that all personnel authorised to Process Customer Data are bound by contractual or statutory confidentiality obligations that expressly cover patient health data, and receive data-protection and security training. 4.3 Security. Implement and maintain the technical and organisational measures in the security-measures annex to this DPA, and not materially degrade them during the term. That annex is versioned; Vanta notifies the Customer of material updates. 4.4 Sub-processors.   (a) The Customer grants general authorisation for the Sub-processors listed in the approved sub-processor annex to this DPA and in Vanta's current sub-processor register, which is available at healthease.app/legal and on request from info@healthease.app.   (b) Vanta gives the Customer at least 30 days' prior notice of any new or replacement Sub-processor. The Customer may object on reasonable data-protection grounds within that window; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receives a pro-rata refund of prepaid fees for the unused period.   (c) Vanta imposes on each Sub-processor, by written contract, data-protection obligations no less protective than this DPA, and remains fully liable to the Customer for its Sub-processors' performance. 4.5 Assistance with Data Subject rights. Taking into account the nature of the Processing, assist the Customer with appropriate technical and organisational measures — including the Service's built-in export, rectification, erasure, portability, and disclosure-accounting tooling — in fulfilling the Customer's obligations to respond to Data Subject requests. Service levels: Vanta acknowledges an assistance request within 72 hours and provides fulfilment support within 30 days. If a Data Subject contacts Vanta directly, Vanta will (unless legally prohibited) refer the request to the Customer rather than respond on the merits. 4.6 Assistance with compliance. Taking into account the nature of the Processing and the information available to it, assist the Customer with security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities, to the extent required by Applicable Data Protection Law. 4.7 Personal Data Breach. Notify the Customer without undue delay and in any event within 72 hours of confirming a Personal Data Breach affecting Customer Data, with (to the extent known, supplemented as information becomes available): the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, measures taken or proposed, and a contact point. Vanta maintains a documented incident-response and breach-notification runbook and provides the Customer with the information reasonably needed to meet the Customer's own notification duties, including a securely delivered list of affected patients and template patient communications. Vanta's notification is not an admission of fault. 4.8 Deletion and return. On termination or expiry of the Agreement, Vanta provides a 60-day window during which the Customer may export all Customer Data via the Service's full-export tooling (human-readable and machine-readable formats). After the window (or earlier at the Customer's written request), Vanta deletes Customer Data, including by destruction of the Customer's data-encryption keys so that backup copies are rendered permanently unreadable ("crypto-shredding"), and issues a deletion certificate — except to the extent law applicable to Vanta requires continued retention, in which case the data remains protected under this DPA and is isolated from further Processing. 4.9 Records and audit.   (a) Vanta maintains records of its Processing activities as required by Applicable Data Protection Law.   (b) Vanta makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA — primarily by furnishing its then-current security documentation, control matrix, and third-party audit reports or attestations as they become available.   (c) Where those materials are insufficient to satisfy a legal requirement of the Customer, the Customer (or an independent auditor bound to confidentiality, not a Vanta competitor) may audit Vanta's compliance: maximum once per 12-month period (more often after a Personal Data Breach affecting the Customer), on ≥30 days' notice, during business hours, without access to other customers' data, and at the Customer's cost. Findings are confidential. 4.10 Data location. Vanta Processes and stores Customer Data in the hosting region selected for the Customer's account — by default with a reputable cloud infrastructure provider operating in the Asia-Pacific (Singapore) region under appropriate data-protection safeguards — and, where disaster-recovery replication is enabled, in the encrypted-backup region recorded in the approved sub-processor annex. Customer Data is not stored in India or the Middle East. Vanta gives the Customer prior notice of any change to the storage regions applicable to its account; a region change is treated as a Sub-processor change, carrying the same 30-day notice, objection, and termination-with-refund rights described above.

5. Customer (Controller) obligations

The Customer:

5.1 is solely responsible for the lawfulness of its Processing, including establishing and documenting a lawful basis for collecting patient data, providing legally required notices, and obtaining any required patient consent (the Service provides consent-capture tooling, including a distinct recorded consent scope for cross-border storage, but the legal responsibility for the consent's validity is the Customer's); 5.2 is responsible for the accuracy and quality of Customer Data, for its users and their access rights (unique logins per staff member, no credential sharing, prompt deactivation of departed staff), and for the security of its own devices, networks, and printed outputs; 5.3 will use the Service's controls (roles, permissions, retention settings) in a manner consistent with Applicable Data Protection Law, and will not instruct Vanta to Process Customer Data unlawfully; 5.4 acknowledges that the Service is administrative/practice-management software, is not a medical device, and is not intended or represented to diagnose, treat, cure or prevent any disease or to provide clinical, diagnostic or treatment advice; that clinical decisions, diagnosis, treatment, and patient care remain solely the responsibility of the Customer and its clinicians; and that the Customer is responsible for independently verifying the accuracy and completeness of any Customer Data before relying on it for clinical, billing or regulatory purposes.

6. Shared responsibility

Security of the Service is shared: Vanta is responsible for the platform-side measures in the security-measures annex; the Customer is responsible for the customer-side measures described in its Controller obligations above and in the customer part of the security-measures annex. Vanta is not responsible for unauthorised access resulting from the Customer's failure to meet its responsibilities (including credential sharing or failure to deactivate departed staff).

The Service records patient consent as separate, purpose-specific scopes: CARE_RECORD, OFFSHORE_PROCESSING, AI_PROCESSING, DATA_SHARING_RESEARCH, and MR_HISTORY, each with status, notice version, capture method, and recording user, on an append-only history. The Customer will use this tooling (or equivalent documented processes) to evidence patient consent where consent is the Customer's lawful basis, and will file any signed paper consent slips it collects.

8. International transfers

8.1 The parties acknowledge that Customer Data is stored in the region(s) stated in the data-location commitment above and in the approved sub-processor annex, and that the Customer's use of the Service may therefore involve an international transfer of Personal Data. 8.2 Transfer safeguards: this DPA; the technical measures in the security-measures annex (including encryption in transit and at rest and field-level encryption under keys controlled by Vanta in the hosting region); and, where the Customer relies on consent, the recorded OFFSHORE_PROCESSING consent scope. 8.3 Where Applicable Data Protection Law requires a prescribed transfer mechanism (e.g., EU Standard Contractual Clauses, the UK IDTA/Addendum, or an equivalent), the parties incorporate the applicable mechanism by reference as an addendum to this DPA, with this DPA's annexes (the details of processing, the security measures, and the approved sub-processor list) serving as the corresponding appendices, and will, at either party's written request, execute the applicable mechanism in the form required by that law.

9. Liability

9.1 Cap. Each party's total aggregate liability arising out of or related to this DPA is subject to, counts towards, and does not increase and is not in addition to, the exclusions, the per-claim limits and the aggregate limitation of liability set out in the Agreement (the master terms). Those exclusions and limits apply to the parties' liability under this DPA and under any incorporated transfer mechanism in aggregate. Nothing in this DPA is intended to, or shall, increase either party's liability beyond the limits stated in the Agreement. 9.2 Excluded losses. To the maximum extent permitted by applicable law, and subject always to the non-excludable-liability carve-out below, neither party is liable to the other for any indirect, incidental, special, consequential, exemplary or punitive damages, or for any loss of profit, revenue, anticipated savings, business, contracts or goodwill, or loss of or corruption of data, in each case whether arising in contract, tort (including negligence), breach of statutory duty or otherwise, and whether or not the loss was foreseeable or the party was advised of its possibility. 9.3 No absolute-security warranty; third-party events. The security and technical and organisational measures in the security-measures annex and elsewhere in this DPA are provided on an "as is" and "as available" basis. Vanta undertakes to implement and maintain reasonable and appropriate measures as described but, to the maximum extent permitted by applicable law and subject always to the non-excludable-liability carve-out below, does not warrant or guarantee that the Service or any security measure will be uninterrupted or error-free, or that the security, transmission or storage of data will be absolute; and, to that extent, all other warranties, conditions and terms (whether express, implied or statutory) are excluded. Neither party is liable for delay or failure caused by events beyond its reasonable control (including force majeure and failures of infrastructure, networks, utilities or third-party services not engaged by Vanta as a Sub-processor), save that nothing in this paragraph reduces Vanta's responsibility for its Sub-processors, for whose performance it remains fully liable as stated above. 9.4 Non-excludable liability (carve-out). Nothing in this DPA or the Agreement excludes or limits either party's liability to the extent it cannot lawfully be excluded or limited, including: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; gross negligence or wilful misconduct where such liability cannot lawfully be limited; any Data Subject rights, remedies or compensation and any supervisory-authority powers under Applicable Data Protection Law that cannot be contractually waived; and any other liability that applicable law does not permit to be excluded or limited.

10. Indemnity

To the extent permitted by applicable law, the Customer will indemnify Vanta against third-party claims (including claims by Data Subjects or regulators) to the extent arising from the Customer's breach of this DPA, its lack of a lawful basis for Customer Data, its unlawful instructions, or its failure to meet its Controller obligations — subject to the indemnification procedure in the Agreement.

11. Law-enforcement and government requests

If Vanta receives a legally binding request for Customer Data from a public authority, Vanta will: validate the legal instrument; challenge or narrow overbroad requests where reasonably possible; disclose only the minimum lawfully required; log the disclosure; and notify the Customer promptly unless legally prohibited from doing so.

12. Term

This DPA is effective for as long as Vanta Processes Customer Data and survives termination of the Agreement to that extent (including through the deletion and return process described above).

13. Order of precedence

For Personal Data matters: (1) any incorporated statutory transfer mechanism; (2) this DPA, including any express written amendment to it in a signed Order Form; (3) the Agreement (the signed Order Form, then the HealthEase Subscription Agreement).

14. Governing law and forum

This DPA is governed by the laws of Pakistan, and the courts of Islamabad have exclusive jurisdiction, except where an incorporated transfer mechanism mandates otherwise for its own terms.

15. Execution

This DPA is executed either by countersignature of the signature blocks below or by the Customer's online acceptance during onboarding, whichever the parties use; in each case Vanta retains a record of the accepted version and the date of acceptance. HealthEase's onboarding records DPA execution as a gating event before patient-data modules are activated.

Vanta (Private) Limited Signature: ______________________ Name: ______________ Title: ______________ Date: __________

Customer Signature: ______________________ Name: ______________ Title: ______________ Date: __________


Annex I — Details of Processing

A. Parties.

  • Data exporter / Controller: the Customer (healthcare provider) identified in the Agreement.
  • Data importer / Processor: Vanta (Private) Limited, a company incorporated in Pakistan. Contact: info@healthease.app.

B. Subject matter. Provision of the HealthEase clinic and hospital management service (hosted service and Windows/Android/iOS applications).

C. Duration. The term of the Agreement, plus the post-termination 60-day export window and deletion process described in this DPA.

D. Nature of the Processing. Hosting, storage, structuring, retrieval, display, transmission to the Customer's authorised users, backup, deletion, and — only where separately agreed in advance in writing and consented — AI-assisted processing; all performed as software-service operations on the Customer's behalf.

E. Purposes. Operating the Service modules the Customer has subscribed to and configured: patient registration and records, visits and queue management, clinical documentation, prescriptions, billing/receipts, pharmacy dispensing (where licensed), staff and attendance management, and reporting.

F. Categories of Data Subjects.

  • Patients of the Customer (including minors, via guardian);
  • Guardians / next of kin;
  • The Customer's staff and other authorised users.

G. Categories of Personal Data.

  • Patient identity and demographics: name, date of birth, gender, national identity number (e.g., CNIC), contact details, address, guardian relation, medical record number;
  • Special-category / sensitive data: health data — visit records, diagnoses, prescriptions, vitals, nursing charts, lab notes, clinical documents, dispensing records;
  • Consent records;
  • Operational data: appointments, queue tokens, room assignments, timestamps;
  • The Customer's billing records relating to patients (no patient payment-card or bank credentials are stored);
  • Staff data: profiles, roles, contact details, attendance/roster records, activity logs.

H. Sensitive-data safeguards. Field-level encryption of identifying and clinical fields, purpose-scoped recorded consent, role-based least-privilege access, immutable audit logging, and the further measures in the security-measures annex.

I. Frequency. Continuous, for the duration of the Agreement.

J. Retention. Per the Service's retention schedule as configured by the Customer, subject to platform defaults and legal floors (e.g., adult clinical records 12 years by default; financial records 7 years; audit logs 12 years; Customer-terminated data: 60-day export window then deletion). The Customer's configured schedule forms part of its documented instructions.


Annex II — Technical and Organisational Security Measures

These are the technical and organisational measures Vanta implements and maintains, or is progressively implementing, as part of its security program, updated under the DPA's security commitment (which does not permit material degradation) and this annex's versioning. They describe the measures Vanta applies to protect Customer Data; where a particular measure is not yet fully in production, Vanta is committed to implementing and maintaining it as part of that program. As stated in the DPA's liability terms, they are provided on an "as is" and "as available" basis and, to the maximum extent permitted by applicable law, do not constitute a warranty or guarantee of uninterrupted, error-free or absolute security.

Part A — Vanta (platform) measures.

  1. Encryption. TLS 1.2+ for all data in transit. Encryption at rest for all data stores and backups. Additional field-level AES-256-GCM encryption of patient-identifying and clinical fields under per-Customer data-encryption keys, with managed key hierarchy, key rotation, and keys resident in the hosting region. Deletion into backups is achieved by destruction of the relevant keys (crypto-shredding).
  2. Access control. Unique named accounts; multi-factor authentication supported and enforced for privileged/administrative roles; role-based, deny-by-default authorisation enforced server-side on every request; session idle-lock. No standing Vanta staff access to production Customer Data; emergency break-glass access is exceptional, time-boxed, dual-controlled, and fully audited.
  3. Tenant isolation. Each Customer's data is logically isolated; the isolation boundary is derived from validated authentication tokens server-side and is covered by automated isolation testing.
  4. Audit logging. Every data-changing action is recorded in a tamper-evident (hash-chained) audit log mirrored to write-once storage, with regular integrity verification. Audit logs are retained at least as long as the records they evidence.
  5. Network and application security. Web application firewall, rate limiting, request throttling, input validation on every command, and no caching of patient data at the network edge.
  6. Logging hygiene. Patient-identifying data is excluded from application logs, error traces, and analytics by a redacting logging layer.
  7. Vulnerability and change management. Version-controlled infrastructure as code; peer-reviewed changes through CI/CD with automated security checks; dependency and vulnerability scanning with defined patch SLAs; periodic penetration testing.
  8. Monitoring and incident response. Security monitoring and alerting; a documented incident-response plan with severity matrix and the 72-hour Controller breach-notification commitment stated in this DPA; incident-response exercises.
  9. Backups and continuity. Automated encrypted backups with point-in-time recovery, defined RPO/RTO objectives, and periodic restore testing. Backup copies remain within the permitted region envelope (never India or the Middle East).
  10. Personnel and organisation. Confidentiality undertakings covering health data; security and privacy training at hire and annually; background verification consistent with local employment law; prompt access revocation on role change or departure; a maintained information-security policy register. Vanta designs its security program with reference to recognised frameworks such as ISO/IEC 27001 and SOC 2, and does not currently hold, or claim, certification against those standards.
  11. Data minimisation. Patient data never appears in the platform administration plane; analytics available to Vanta are aggregate counts and rates only; de-identification standards apply to any secondary aggregate use.

Part B — Customer measures (shared responsibility).

  1. Unique logins per staff member; no credential sharing; strong passwords; enabling MFA where offered.
  2. Prompt deactivation of departed or role-changed staff in the Service.
  3. Device security at the point of care: OS-level device encryption, screen lock, physical control of devices holding the Service's offline working data, and secure handling/disposal of printed outputs.
  4. Accurate data entry, lawful collection, patient notices and consent, and filing of signed paper consent slips.
  5. Configuration of roles, permissions, and retention settings appropriate to the Customer's legal obligations.

Annex III — Approved Sub-processors

The current, versioned sub-processor register is available at healthease.app/legal and on request from info@healthease.app; changes follow the DPA's sub-processor notice-and-objection process (30 days' prior notice, with a right to object and, if unresolved, to terminate the affected Service with a pro-rata refund). Sub-processors are described below by role; the register identifies each engaged provider by name.

Sub-processor Purpose Data Location Safeguards
Cloud infrastructure provider (primary hosting) — a reputable cloud hosting provider identified in the sub-processor register Hosting, storage, and compute for the Service All Service data, incl. encrypted Customer Data Asia-Pacific (Singapore) — primary region (Customer-selectable from offered regions; never India or the Middle East) Provider data-processing addendum; the provider's own independently audited security certifications; appropriate data-protection safeguards
Cloud infrastructure provider (secondary region) Optional encrypted disaster-recovery backups, only where enabled for the Customer's account Encrypted backups only A permitted non-India, non-Middle-East region recorded on the Customer's account Same as above; encrypted-backup-only exposure
Cloud infrastructure provider (certificate and content-delivery control plane) TLS certificate and content-delivery control plane only No Customer Data (technical metadata only) USA Same as above; excluded from Customer Data scope
Email/SMS delivery provider — identified in the sub-processor register Authentication and notification messages Names, contact numbers; no clinical content in message bodies As recorded in the sub-processor register Data-processing terms + content-minimisation rule
Error monitoring / diagnostics provider — identified in the sub-processor register Service reliability and diagnostics Technical telemetry; no patient-identifying data (redaction enforced) As recorded in the sub-processor register Data-processing terms + the logging-hygiene rule in the security-measures annex
United Bank Limited (UBL) — online payment gateway (also listed in the sub-processor register) Online payment processing / card acquiring for subscription and Service fees Customer billing contact and transaction data only (amount, currency, status, tokenised payment reference); no patient data and no clinical Customer Data Pakistan UBL's own data-processing and PCI-DSS-compliant terms; boundary rule that no patient data crosses to payment systems

Online payments for subscription and Service fees are handled through the UBL payment gateway operated by United Bank Limited (UBL), a licensed commercial bank in Pakistan, listed above. Payment-card details are captured and processed directly by UBL under its own PCI-DSS-compliant terms; Vanta does not receive or store full payment-card numbers. No patient data is involved in billing, and no patient data crosses to payment systems. Any new or replacement payment provider is added to the register under the DPA's sub-processor notice-and-objection process.


Vanta (Private) Limited — a company incorporated in Pakistan. Contact: info@healthease.app · healthease.app

Ready when you are

See HealthEase running your clinic — before you decide.

Book a free demo. We'll walk you through the system on a real screen, answer every question, and never rush you.

Book a free demo