Commercial legal

Health Data Addendum

Processor safeguards and privacy allocation for clinic-directed service data.

Technologies Enodo Inc. ("Enodo")

Effective: August 24, 2026 · Version: 2026-08-24-draft-counsel-review

Email the Privacy Officer

Launch gate

This bilingual implementation draft requires privacy and legal review before public launch, including review of applicable provincial and cross-Canada requirements.

1. Roles and instructions

The customer determines the purposes and means of clinic-directed enodoCare and clinic-linked enodoAlly information and remains responsible for patient-facing privacy obligations. Enodo acts on documented customer instructions to provide, secure, support, and improve the contracted services. Patient clinic-link consent authorizes the link; it does not transfer the customer’s responsibilities to Enodo.

2. Safeguards and confidentiality

Enodo applies administrative, technical, and physical safeguards proportionate to the sensitivity of the data, restricts access to authorized personnel, and binds personnel to confidentiality. Enodo maintains incident procedures and notifies the customer of a confirmed breach involving Customer Data without undue delay, subject to lawful restrictions.

3. Subprocessors and locations

Enodo may use vetted subprocessors for hosting, infrastructure, AI inference, communications, support, and payments under written privacy and security obligations. Stripe is a payment subprocessor that sees the identified customer organization and aggregate commercial usage quantities. Processing locations and subprocessor commitments are documented for customers and reviewed before a material change.

4. Assistance, verification, and records

Enodo reasonably assists the customer with access, correction, export, incident, and verification requests within the limits of the service. The customer may request available information needed to assess Enodo’s performance under this addendum, subject to confidentiality, security, and other customers’ rights.

5. Return, retention, and deletion

At termination, the 90-day administrator read and export period applies. Enodo then deletes or de-identifies Customer Data under retention-controlled procedures, except where limited retention is required for law, security, backups, dispute resolution, audit, or enforcement. Deletion from backups follows the applicable backup lifecycle.