Legal
Last updated:
This Data Processing Addendum ("DPA") is part of the Terms of Service between Harper Grace Solutions LLC ("Processor", "we", or "us") and the business customer ("Controller" or "you") using SpinaCareSync for care coordination. It sets out the rules for how we handle personal data on your behalf when you use our service as a business or organization.
This DPA uses plain English. If anything conflicts with your main service agreement, this DPA controls for data protection matters.
This DPA applies when you use SpinaCareSync as a business, clinic, care agency, or other organization that handles personal data about clients, patients, or their families through the app. It does not apply to consumers using SpinaCareSync for their own family.
If you use our service to process data on behalf of another organization, you must ensure you have permission to authorize us as a subprocessor.
The data entered and stored in SpinaCareSync may include information about the children and families you support, such as:
This is typically sensitive personal and health-related data. We treat it as such.
We process the data only to:
We do not use this data for our own advertising, profiling, or unrelated commercial purposes.
Your instructions are the actions your authorized users take inside the app: adding records, inviting team members, setting permissions, configuring reminders, and deleting data. If you ask us to do something with data that goes beyond what the app normally allows, we will confirm it in writing where required.
We implement administrative, technical, and physical safeguards to protect the data you entrust to us, including:
We use trusted infrastructure providers to host and operate SpinaCareSync. Our main hosting and database services are provided by Lovable Cloud. We remain responsible for any subprocessors we engage, and we ensure they meet equivalent security and confidentiality obligations.
If you need a current list of subprocessors or want to be notified of material changes, contact us through our Support page.
We keep personal data for as long as your account is active and as needed to provide the service. When you delete data inside the app, it is permanently removed from active systems. If you terminate your account, we delete or anonymize data according to our data retention schedule, except where we are legally required to keep it.
As the controller, you agree to:
If an individual asks you to access, correct, delete, or restrict the use of their personal data, you should handle the request as the controller. We will assist you by making available the tools in SpinaCareSync to view, edit, export, or delete the data you hold. If you need help with a request you cannot complete yourself, contact us through our Support page.
You may request reasonable information about our security and data protection practices. We will provide a summary of our controls, certifications where applicable, and responses to written security questionnaires. Onsite audits are not normally required, but we will discuss them in good faith if a specific legal or regulatory need arises.
SpinaCareSync is operated from the United States. If you are located outside the United States, your data may be stored and processed there. We handle such transfers using appropriate safeguards, including standard contractual protections and security measures, to ensure data is protected consistently with this DPA.
We may update this DPA to reflect changes in law or our service. We will post the updated version with a new "Last updated" date and notify you of material changes. This DPA terminates automatically when your paid service agreement ends and all data has been returned or deleted in line with Section 8.
If you have questions about this Data Processing Addendum, please reach out through our Support page.
Questions about this page? Reach us through our Support page.