📋 About This Agreement
This Data Processing Agreement ("DPA") is a template provided by Universum Global Solutions LLC for review prior to execution. It is entered into between UniversumGS (as Data Processor) and the Customer organization identified in a signed Order Form or Master Services Agreement (as Data Controller). This template becomes binding only upon countersignature by both parties.
For questions or to initiate execution, contact: legal@universumgs.com
1. Parties & Definitions
Parties
Data Processor ("Processor"): Universum Global Solutions LLC, a limited liability company organized in the United States, operating the VerifyMed platform.
Data Controller ("Controller" or "Customer"): The healthcare facility, hospital system, or organization identified in the applicable Order Form or Master Services Agreement who has engaged Processor to provide VerifyMed services.
Definitions
• "Personal Data" means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller in connection with the VerifyMed services.
• "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
• "Services" means the VerifyMed healthcare supply chain compliance platform, including device scanning, invoice processing, compliance reporting, and dashboard analytics.
• "Sub-processor" means any third party engaged by Processor to process Personal Data in connection with the Services.
• "Data Breach" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
• "Applicable Data Protection Law" means all applicable privacy and data protection laws, including HIPAA (where applicable), CCPA, and other applicable US federal and state laws.
2. Scope of Processing
Nature and Purpose
Processor processes Personal Data solely to provide the Services to Controller, including:
• Authenticating authorized facility personnel who access the VerifyMed platform
• Processing device scan records (UDIs, GTINs, scan timestamps, facility and department associations) to perform product verification and recall checks
• Processing uploaded supplier invoices to extract device identifiers and validate against regulatory databases
• Generating compliance reports, dashboards, and analytics for Controller's authorized users
• Storing and retrieving historical scan and invoice data for Controller's compliance records
Categories of Personal Data
The Personal Data processed under this DPA is limited to:
• Authorized user names and email addresses (facility personnel)
• User authentication credentials (hashed; never stored in plaintext)
• Scan activity records associated with user accounts (device identifier scanned, timestamp, facility, department)
• Invoice metadata associated with user accounts (vendor name, upload timestamp, processing results)
Categories of Data Subjects
Authorized facility personnel (hospital staff, supply chain teams, procurement officers) designated by Controller to access VerifyMed.
No Patient Data
VerifyMed is not designed or intended to process patient information. Controller agrees not to input, upload, or otherwise submit any Protected Health Information (PHI) as defined under HIPAA, patient identifiers, or any data that directly identifies patients into the VerifyMed platform. Processor has no obligation to process such data and accepts no liability for any PHI inadvertently submitted by Controller.
3. Processor Obligations
Processing Instructions
Processor shall process Personal Data only on documented instructions from Controller, as set forth in this DPA and the applicable Order Form. Processor shall promptly inform Controller if, in its opinion, any instruction infringes Applicable Data Protection Law.
Confidentiality
Processor shall ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations. Processor shall not disclose Personal Data to third parties except as necessary to provide the Services or as required by applicable law.
Security Measures
Processor shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against Data Breaches, including:
• Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256)
• Access controls limiting Personal Data access to authorized personnel on a need-to-know basis
• Multi-factor authentication for administrative access to production systems
• Regular security assessments and vulnerability management
• Audit logging of access to Personal Data
• Data hosted on AWS infrastructure in the United States with SOC 2 Type II certification
Sub-processors
Controller authorizes Processor to engage the following Sub-processors in connection with the Services:
• Amazon Web Services (AWS) — Cloud infrastructure, data storage (S3), and compute (EC2, RDS). Data hosted in US-East-1 region.
• Anthropic — AI processing for invoice line-item extraction and device identification via Claude API. Only invoice content and device identifiers are transmitted; no user personal data beyond what is necessary for the task.
• FDA / Health Canada — Public regulatory databases queried for recall and device registration data; no Personal Data is transmitted to these sources.
Processor shall notify Controller of any intended addition or replacement of Sub-processors with at least 30 days' notice, providing Controller the opportunity to object. If Controller objects on reasonable data protection grounds, the parties shall work in good faith to resolve the objection.
Data Breach Notification
Processor shall notify Controller without undue delay, and in any event within 72 hours, after becoming aware of a Data Breach affecting Personal Data processed on Controller's behalf. Notification shall include, to the extent available: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
Data Subject Rights
Processor shall provide Controller with reasonable assistance to fulfil Controller's obligations to respond to data subject rights requests (access, correction, deletion, portability) to the extent that such requests relate to Personal Data processed by Processor on Controller's behalf.
Deletion & Return of Data
Upon termination of the Services or upon Controller's written request, Processor shall, at Controller's election, securely delete or return all Personal Data processed on Controller's behalf within 60 days. Processor may retain anonymized or aggregated data that cannot reasonably identify any individual after deletion. Processor shall certify deletion in writing upon Controller's request.
Audits
Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with this DPA and shall permit and contribute to audits conducted by Controller or a mandated auditor, provided that: (a) Controller provides at least 30 days' prior written notice, (b) audits are conducted during normal business hours, (c) audits do not unreasonably disrupt Processor's operations, and (d) Controller bears its own costs of audit unless the audit reveals a material non-compliance by Processor.
4. Controller Obligations
Controller represents and warrants that:
• It has the legal authority and all necessary rights to provide Personal Data to Processor for processing under this DPA
• It has provided all required notices to, and obtained all necessary consents from, data subjects whose Personal Data is submitted to the Services
• It will only submit Personal Data to the Services for the purposes described in this DPA
• It will not submit any PHI, patient identifiers, or Special Category Data (as defined under applicable law) to the Services
• It will promptly notify Processor of any changes to its processing instructions that may affect Processor's obligations under this DPA
5. Data Retention
Unless otherwise specified in a signed Order Form, Processor retains Personal Data as follows:
• User account and authentication data: Duration of active subscription plus 1 year following contract termination
• Device scan records: 7 years from date of scan, to support healthcare regulatory compliance requirements
• Invoice upload records and line-item data: 7 years from date of upload
• Compliance reports and dashboard data: 7 years
• Audit logs: 3 years
Controller may request early deletion of its data at any time by contacting privacy@universumgs.com. Early deletion may affect the completeness of compliance history available to Controller.
6. International Transfers
All Personal Data processed under this DPA is stored and processed within the United States on AWS infrastructure. Processor does not transfer Personal Data to countries outside the United States without Controller's prior written consent, except where required by applicable law. If Controller is located outside the United States and applicable law requires additional transfer mechanisms (such as Standard Contractual Clauses), the parties agree to execute such additional documents as reasonably necessary.
7. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Master Services Agreement or Order Form between the parties. In the absence of such an agreement, each party's total liability under this DPA shall not exceed the fees paid by Controller to Processor in the 12 months preceding the claim giving rise to liability.
8. Term & Termination
This DPA is effective from the date of countersignature by both parties and remains in force for the duration of Processor's provision of Services to Controller under the applicable Order Form or Master Services Agreement. This DPA automatically terminates upon expiry or termination of the underlying Services agreement, except that obligations relating to data deletion, confidentiality, and audit rights shall survive for a period of 2 years following termination.
9. Governing Law
This DPA is governed by and construed in accordance with the laws of the State of New Jersey, United States. Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the applicable Master Services Agreement, or, in the absence thereof, by the courts of New Jersey.
10. Signatures
By signing below, the parties agree to be bound by the terms of this Data Processing Agreement.
Data Processor
Universum Global Solutions LLC
Data Controller (Customer)
Organization Name: _______________________
Executed copies of this DPA should be sent to legal@universumgs.com.
11. Contact
Data Protection inquiries: privacy@universumgs.com
Legal / Contract inquiries: legal@universumgs.com