Data Processing Agreement

Version: 1.0

Effective Date: July 20, 2026

Important: This Data Processing Agreement ("DPA") forms part of the Birch Terms of Service and applies when 28labs Inc. processes personal data on behalf of customers as a data processor under the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. DEFINITIONS

In this DPA, the following terms shall have the meanings set out below:

  • "Agreement" means the Birch Terms of Service and any applicable Order Forms or subscription agreements
  • "Controller" means the entity which determines the purposes and means of the processing of Personal Data
  • "Customer" means the healthcare organization or healthcare professional subscribing to Birch Services
  • "Data Protection Laws" means GDPR and any other applicable data protection or privacy laws
  • "Data Subject" means an identified or identifiable natural person
  • "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation)
  • "Personal Data" means any information relating to a Data Subject
  • "Processing" means any operation performed on Personal Data
  • "Processor" means the entity which processes Personal Data on behalf of the Controller
  • "Security Incident" means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data
  • "Services" means the Birch AI-powered patient communication and workflow automation services
  • "Sub-processor" means any third party engaged by Processor to process Personal Data
2. RELATIONSHIP OF THE PARTIES

2.1 Roles: The parties acknowledge and agree that with regard to the processing of Personal Data:

  • Customer is the Controller
  • 28labs Inc. (Birch) is the Processor
  • Birch will process Personal Data only on behalf of and in accordance with Customer's documented instructions

2.2 Customer Instructions: Customer instructs Birch to process Personal Data:

  • To provide the Services in accordance with the Agreement
  • As documented in the use of the Services by authorized users
  • As further documented in any written instructions provided by Customer
  • As required to comply with applicable laws

2.3 Prohibited Data: Customer shall not submit to the Services any Personal Data that:

  • Is not necessary for the provision of healthcare services
  • Relates to criminal convictions and offenses unless legally authorized
  • Customer is not authorized to process under applicable laws
3. PROCESSING OF PERSONAL DATA

3.1 Purpose Limitation: Birch shall process Personal Data only for the following purposes:

  • Handling of patient calls, texts, chat, and email
  • Appointment scheduling, reminders, and intake
  • Billing support and payment link delivery
  • Storage and retrieval of communication records
  • Technical support and service improvement
  • Compliance with legal obligations

3.2 Duration: Birch shall process Personal Data for the duration of the Agreement unless:

  • Customer requests deletion of specific Personal Data
  • Processing is required by applicable law beyond termination
  • Personal Data is required for the establishment, exercise, or defense of legal claims

3.3 Confidentiality: Birch shall ensure that:

  • All personnel authorized to process Personal Data have committed to confidentiality
  • Access to Personal Data is limited to personnel who require such access
  • Personnel receive appropriate training on data protection obligations
4. DATA SUBJECT RIGHTS

4.1 Assistance with Requests: Birch shall assist Customer in fulfilling its obligations to respond to Data Subject requests by:

  • Implementing appropriate technical and organizational measures
  • Providing Customer with the ability to access, correct, and delete Personal Data
  • Notifying Customer promptly of any Data Subject requests received directly
  • Not responding to Data Subject requests directly unless authorized by Customer

4.2 Data Subject Rights Include:

  • Right of access to Personal Data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Rights related to automated decision-making
5. SECURITY MEASURES

5.1 Technical and Organizational Measures: Birch implements and maintains the following security measures:

  • Encryption: AES-256 encryption for data at rest and TLS 1.3 for data in transit
  • Access Control: Role-based access control, multi-factor authentication, and principle of least privilege
  • Data Centers: SOC 2 Type II certified data centers with 24/7 monitoring
  • Network Security: Firewalls, intrusion detection systems, and DDoS protection
  • Backup and Recovery: Regular encrypted backups with tested recovery procedures
  • Vulnerability Management: Regular security assessments and penetration testing
  • Incident Response: Documented incident response procedures
  • Employee Security: Background checks, security training, and confidentiality agreements

5.2 Security Updates: Birch shall:

  • Regularly review and update security measures
  • Apply security patches and updates promptly
  • Maintain security measures at industry standard levels
  • Notify Customer of material changes to security measures
6. SUB-PROCESSORS

6.1 Authorized Sub-processors: Customer provides general authorization for Birch to engage Sub-processors subject to:

  • Birch maintaining a current list of Sub-processors
  • Birch notifying Customer of intended changes to Sub-processors
  • Customer having the right to object to new Sub-processors
  • Sub-processors being bound by data protection obligations no less protective than this DPA

6.2 Current Sub-processors:

  • Amazon Web Services (AWS): Cloud infrastructure and storage
  • Google Cloud Platform: AI/ML processing services
  • SendGrid: Transactional email services
  • Stripe: Payment processing

A complete and updated list is available at /support

6.3 Objection Rights:

  • Customer may object to new Sub-processors within 30 days of notification
  • If Customer objects, Birch will use reasonable efforts to provide alternative solutions
  • If no alternative is available, Customer may terminate the affected Services
7. INTERNATIONAL TRANSFERS

7.1 Transfer Mechanisms: For transfers of Personal Data outside the EEA, Birch shall ensure:

  • Implementation of EU Standard Contractual Clauses (Module 2: Controller to Processor)
  • Supplementary measures including encryption and access controls
  • Transfer impact assessments where required
  • Compliance with Chapter V of the GDPR

7.2 Transfer Notifications: Birch shall:

  • Notify Customer of any intended transfers to new countries
  • Provide information about transfer safeguards upon request
  • Assist Customer with transfer impact assessments
8. DATA BREACH NOTIFICATION

8.1 Notification Requirements: In the event of a Security Incident, Birch shall:

  • Notify Customer without undue delay and within 48 hours of becoming aware
  • Provide all available information about the incident including:
    • Nature of the breach and categories of data affected
    • Likely consequences of the breach
    • Measures taken or proposed to address the breach
    • Contact details for more information
  • Cooperate with Customer in investigating the incident
  • Document all breaches and remediation measures

8.2 Remediation: Birch shall:

  • Take immediate steps to mitigate the effects of the breach
  • Implement measures to prevent recurrence
  • Assist Customer in complying with breach notification obligations
  • Not publicly disclose the breach without Customer's prior written consent
9. AUDIT RIGHTS

9.1 Information and Audit: Birch shall:

  • Make available all information necessary to demonstrate compliance
  • Allow for and contribute to audits conducted by Customer or an auditor mandated by Customer
  • Provide annual SOC 2 Type II or similar third-party audit reports
  • Maintain records of all processing activities

9.2 Audit Procedures:

  • Customer shall provide 30 days written notice for audits
  • Audits shall be conducted during business hours
  • Customer shall bear the costs of audits unless material non-compliance is discovered
  • Audits shall not unreasonably interfere with Birch's business operations
10. RETURN AND DELETION OF DATA

10.1 Upon Termination: Birch shall, at Customer's election:

  • Return all Personal Data to Customer in a structured, commonly used format
  • Delete all Personal Data and existing copies
  • Certify in writing the deletion of Personal Data

10.2 Exceptions: Birch may retain Personal Data to the extent required by:

  • Applicable laws or regulations
  • Professional standards for healthcare documentation
  • Legitimate interests in defending legal claims
11. INSURANCE AND LIABILITY

11.1 Insurance Requirements: Birch maintains the following insurance coverage:

  • Cyber Liability Insurance: Minimum $10 million per occurrence
  • Professional Liability/E&O Insurance: Minimum $5 million per occurrence
  • General Liability Insurance: Minimum $2 million per occurrence
  • Data Breach Insurance: Including costs of notification, credit monitoring, and regulatory fines

11.2 Proof of Insurance: Upon Customer's request, Birch shall provide certificates of insurance evidencing the required coverage.

12. SECURITY CERTIFICATIONS

12.1 Current Certifications: Birch maintains or is working towards the following certifications:

  • SOC 2 Type II: Annual audit covering security, availability, processing integrity, confidentiality, and privacy
  • ISO 27001: Information security management system certification (in progress)
  • HIPAA Compliance: Regular third-party assessments of HIPAA compliance
  • ISO 27701: Privacy information management certification (planned)

12.2 Audit Reports: Birch shall provide Customer with:

  • Executive summaries of audit reports upon request
  • Full audit reports under NDA for enterprise customers
  • Notification of any material findings or changes in certification status
13. BUSINESS CONTINUITY AND DISASTER RECOVERY

13.1 Business Continuity Plan: Birch maintains a comprehensive business continuity plan that includes:

  • Identification of critical business processes and dependencies
  • Risk assessment and mitigation strategies
  • Emergency response procedures
  • Communication protocols for incidents
  • Annual testing and updates of the plan

13.2 Disaster Recovery:

  • Recovery Time Objective (RTO): 4 hours for critical services
  • Recovery Point Objective (RPO): Maximum 1 hour of data loss
  • Backup Frequency: Continuous replication with hourly snapshots
  • Geographic Redundancy: Data replicated across multiple geographic regions
  • Testing: Quarterly disaster recovery drills with documented results
14. INCIDENT RESPONSE SLAs

14.1 Response Time Commitments:

Incident Severity Initial Response Status Updates Resolution Target
Critical (Data Breach) 1 hour Every 2 hours 24 hours
High (Security Incident) 2 hours Every 4 hours 48 hours
Medium (Service Degradation) 4 hours Daily 5 days
Low (Minor Issue) 24 hours As needed 30 days

14.2 Escalation Procedures:

  • 24/7 security incident hotline for critical issues
  • Dedicated incident manager for Critical and High severity incidents
  • Executive escalation path with defined contact points
  • Post-incident review within 5 business days
15. COMPLIANCE WITH SECTOR-SPECIFIC REGULATIONS

15.1 Healthcare Regulations: Birch ensures compliance with:

  • HIPAA (US): Full compliance with Privacy, Security, and Breach Notification Rules
  • PIPEDA (Canada): Personal Information Protection and Electronic Documents Act compliance
  • Medical Device Regulations: Where applicable, compliance with FDA and CE marking requirements
  • State Medical Privacy Laws: Compliance with state-specific healthcare privacy requirements

15.2 Additional Regulatory Support:

  • Regular regulatory updates and compliance assessments
  • Support for Customer's regulatory audits and inspections
  • Documentation to demonstrate compliance with applicable regulations
  • Notification of regulatory changes affecting data processing
16. LIABILITY AND INDEMNIFICATION

16.1 Liability Cap: Each party's liability under this DPA shall be subject to the limitations set forth in the Agreement, except:

  • As required by applicable Data Protection Laws
  • For willful misconduct or gross negligence
  • For breach of confidentiality obligations

16.2 Indemnification: Each party shall indemnify the other against:

  • Regulatory fines resulting from the indemnifying party's breach of this DPA
  • Third-party claims arising from the indemnifying party's non-compliance
  • Costs and expenses reasonably incurred in defense of such claims
17. COOPERATION AND ASSISTANCE

17.1 Regulatory Cooperation: Birch shall assist Customer in:

  • Responding to inquiries from supervisory authorities
  • Conducting Data Protection Impact Assessments
  • Prior consultation with supervisory authorities where required
  • Demonstrating compliance with Data Protection Laws

17.2 Costs: Customer shall reimburse Birch for reasonable costs incurred in providing assistance beyond Birch's standard obligations.

18. MISCELLANEOUS

18.1 Precedence: In case of conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.

18.2 Modification: This DPA may only be modified by written agreement of both parties, except Birch may update security measures and Sub-processor lists as provided herein.

18.3 Severability: If any provision of this DPA is held invalid, the remaining provisions shall continue in full force and effect.

18.4 No Third-Party Rights: This DPA does not confer any rights on any third party.

19. GOVERNING LAW AND JURISDICTION

This DPA shall be governed by the laws specified in the Agreement, provided that all matters related to the processing of Personal Data shall be governed by applicable Data Protection Laws. Any disputes arising under this DPA shall be subject to the dispute resolution provisions of the Agreement.

SCHEDULE 1: DETAILS OF PROCESSING

Nature and Purpose of Processing:

  • AI-powered handling of patient calls and messages
  • Appointment scheduling and communication management
  • Storage and retrieval of communication records
  • Speech recognition and response generation

Categories of Data Subjects:

  • Patients of Customer
  • Healthcare professionals using the Services
  • Authorized users of Customer

Categories of Personal Data:

  • Patient identification information
  • Medical history and health records
  • Audio recordings of consultations
  • Clinical notes and diagnoses
  • Treatment plans and prescriptions
  • Healthcare professional information

Special Categories of Data:

  • Health data
  • Genetic data (if included in medical records)
  • Biometric data (voice recordings)

Duration of Processing:

For the duration of the Agreement and as required by applicable healthcare regulations and retention requirements.

EXECUTION

This Data Processing Agreement is entered into and becomes a binding part of the Agreement as of the Effective Date of the Agreement.

By using the Birch Services, Customer acknowledges that it has read, understood, and agrees to be bound by this Data Processing Agreement.

For questions regarding this DPA, please contact: support@getbirch.com or visit /support