1. Roles and instructions
The customer determines the purposes and means of clinic-directed enodoCare and clinic-linked enodoAlly information and remains responsible for patient-facing privacy obligations. Enodo acts on documented customer instructions to provide, secure, support, and improve the contracted services. Patient clinic-link consent authorizes the link; it does not transfer the customer’s responsibilities to Enodo.
2. Safeguards and confidentiality
Enodo applies administrative, technical, and physical safeguards proportionate to the sensitivity of the data, restricts access to authorized personnel, and binds personnel to confidentiality. Enodo maintains incident procedures and notifies the customer of a confirmed breach involving Customer Data without undue delay, subject to lawful restrictions.
3. Subprocessors and locations
Enodo may use vetted subprocessors for hosting, infrastructure, AI inference, communications, support, and payments under written privacy and security obligations. Stripe is a payment subprocessor that sees the identified customer organization and aggregate commercial usage quantities. Processing locations and subprocessor commitments are documented for customers and reviewed before a material change.
4. Assistance, verification, and records
Enodo reasonably assists the customer with access, correction, export, incident, and verification requests within the limits of the service. The customer may request available information needed to assess Enodo’s performance under this addendum, subject to confidentiality, security, and other customers’ rights.
5. Return, retention, and deletion
At termination, the 90-day administrator read and export period applies. Enodo then deletes or de-identifies Customer Data under retention-controlled procedures, except where limited retention is required for law, security, backups, dispute resolution, audit, or enforcement. Deletion from backups follows the applicable backup lifecycle.