Legal

Data Processing Agreement

Note: This page contains a template overview of our Data Processing Agreement. The actual binding DPA is executed as part of the customer subscription agreement. All DPA terms should be reviewed by qualified legal counsel before execution.

This Data Processing Agreement ("DPA") forms part of the agreement between HT WORKS Inc ("Processor") and the customer entity ("Controller") and governs the processing of personal data by Residora on behalf of the customer in connection with the Residora platform services.

Scope

This DPA applies where Residora processes personal data on your behalf as part of providing the Residora home healthcare platform. It covers data processed within the platform, including patient records, staff data, scheduling information, billing data, and any other personal data submitted by the customer or collected through use of the service.

Data Processing Terms

Residora will process personal data only on documented instructions from the Controller and for the purposes set out in the subscription agreement. We will not process personal data for our own purposes, sell it to third parties, or use it for advertising. We will inform the Controller if, in our opinion, an instruction infringes applicable data protection law.

Our processing activities are limited to: storing and retrieving data as directed by users of the platform; performing computations necessary to deliver platform features (e.g., scheduling optimisation, billing calculations, AI-assisted documentation); transmitting data to sub-processors as listed below; and providing technical support.

Sub-Processors

We engage sub-processors to assist in delivering the Residora platform. We maintain a current list of sub-processors at residora.care/trust/subprocessors. We will provide advance notice of any intended changes to sub-processors and an opportunity to object. All sub-processors are bound by data processing agreements no less protective than this DPA.

Security Measures

Residora implements appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption of data in transit and at rest, access controls and authentication, regular security assessments, and incident response procedures. Details of our security practices are available at residora.care/trust/security.

Data Subject Rights

We will provide reasonable assistance to the Controller in fulfilling obligations to respond to data subject rights requests, including rights of access, rectification, erasure, restriction, portability, and objection. We will notify the Controller without undue delay upon receiving a data subject rights request that relates to data processed on behalf of the Controller.

Data Breach Notification

In the event of a personal data breach affecting data processed under this DPA, we will notify the Controller without undue delay after becoming aware of the breach and will cooperate in mitigating harm and fulfilling notification obligations to supervisory authorities and affected individuals.

Return and Deletion of Data

Upon termination of the subscription agreement, we will, at the Controller's choice, return or securely delete all personal data processed under this DPA, unless applicable law requires continued retention.

Contact

For DPA-related inquiries, to request a signed DPA, or to exercise rights under this agreement, contact us at legal@residora.care or write to HT WORKS Inc.

This policy was last updated on July 17, 2026. For questions, contact legal@residora.care.