Spread — Legal

    Data Processing Agreement (DPA)

    Processor obligations, sub-processors, international transfers, and breach handling.

    Last updated
    June 1, 2026
    Version
    v1.0.0

    Data Processing Agreement (DPA) — Spread

    Effective date: June 1, 2026 (or, if later, the date both parties execute this DPA)

    This Data Processing Agreement (the "DPA") is entered into between APPHERO TECH LLC, a Nevada limited liability company based in Las Vegas, Nevada, USA, EIN 30-1462085 ("Processor", "apphero"), and the Subscriber that installs the Spread managed package on the Salesforce AppExchange and accepts these terms ("Controller"). Processor and Controller are individually a "Party" and collectively the "Parties".

    This DPA supplements the End User License Agreement (EULA) between the Parties and governs the Processing of Personal Data by Processor on behalf of Controller in connection with the Spread software (the "Service"). Where required by applicable law (notably HIPAA in the United States), this DPA is further supplemented by a separate Business Associate Agreement (BAA), which prevails over this DPA with respect to Protected Health Information ("PHI").


    1. Definitions

    Capitalized terms used and not defined herein have the meanings given in the EULA, the BAA (where applicable), the EU/UK General Data Protection Regulation ("GDPR"), Quebec's Act respecting the protection of personal information in the private sector ("Law 25"), the Belgian Data Protection Act, and HIPAA, as applicable.

    • "Personal Data" means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller under the EULA.
    • "Special Category Data" means Personal Data revealing health, racial or ethnic origin, biometric data for unique identification, or other categories listed in Article 9(1) GDPR.
    • "Processing" has the meaning given in Article 4(2) GDPR.
    • "Subprocessor" means any third party engaged by Processor to Process Personal Data under this DPA.
    • "Data Subject" means a natural person to whom Personal Data relates.
    • "Personal Data Breach" has the meaning given in Article 4(12) GDPR; for US Subscribers, "Breach" has the meaning given in 45 C.F.R. § 164.402.

    2. Scope, roles, and instructions

    2.1 Roles

    Controller is the data controller (and, where HIPAA applies, the Covered Entity or hybrid entity) for the Personal Data Processed under this DPA. Processor is the data processor (and, where HIPAA applies, the Business Associate) acting on Controller's documented instructions.

    2.2 Documented instructions

    Controller's documented instructions to Processor are:

    (a) the EULA and this DPA; (b) the Spread Installation Guide and any configuration documented therein; (c) any reasonable written instruction Controller communicates to Processor by email at dpo@apphero.tech.

    Processor shall not Process Personal Data for any purpose other than these documented instructions and any legal obligation to which Processor is subject. Processor shall promptly inform Controller if, in its opinion, an instruction violates applicable data-protection law.

    2.3 Subject matter, duration, nature, and purpose

    | Field | Value | |---|---| | Subject matter | Provision of the Spread notifiable-disease surveillance Service | | Duration | Term of the EULA + thirty (30) days for return/destruction | | Nature and purpose | Storage, organization, retrieval, transmission, anonymization, and erasure of Personal Data necessary to operate the Service | | Type of Personal Data | Health Concern declarations, Disease Case records, contact-tracing data, vaccination data, alert-subscription data, jurisdiction identifiers, capability tokens, audit logs | | Categories of Data Subjects | Citizens, patients, contacts, health professionals, agency staff, Subscriber authorized users | | Special Category Data | Health data (Article 9 GDPR / PHI under HIPAA) |

    3. Confidentiality

    Processor shall ensure that its personnel authorized to Process Personal Data are bound by appropriate written confidentiality undertakings or are under an appropriate statutory obligation of confidentiality. Confidentiality undertakings survive termination of employment.

    4. Security measures

    Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons.

    The current Spread security measures include, without limitation:

    (a) Encryption at rest (AES-256, native Salesforce platform) and in transit (TLS 1.2+); (b) Access controls via Permission Sets shipped with the Service — least privilege per persona (Citizen Portal, Health Pro Declarant, Health Investigator, Health Officer Admin, Admin); (c) Field-level security enforced manually at every public Apex entry point via the SPR_SecurityUtils helper before any SOQL/DML operation; CRUD/FLS additionally enforced by Salesforce platform via AccessLevel.USER_MODE on all read paths; (d) Sharing controls — all classes with sharing or inherited sharing; per-statement sharing bypass (AccessLevel.SYSTEM_MODE) used only at Guest User entry points and audited; (e) Audit logging — every login-as-subscriber-user event and every anonymization operation is logged immutably; (f) Vulnerability management — continuous Code Analyzer scan on every commit; pre-submission Checkmarx scan; periodic penetration testing on the Next.js portal layer; (g) Incident response procedures aligned with the GDPR Article 33–34 framework and the HIPAA Breach Notification Rule (45 C.F.R. § 164.410); (h) Subprocessor management with written contractual safeguards; (i) Business continuity — leverages the Salesforce platform's high-availability infrastructure (99.95% target uptime).

    A more detailed description is available at https://apphero.tech/spread/security and is updated as security posture evolves.

    5. Subprocessors

    5.1 General authorization

    Controller grants Processor general authorization to engage the Subprocessors listed at https://apphero.tech/spread/legal/subprocessors (the "Subprocessor List"). The Subprocessor List currently includes:

    | Subprocessor | Purpose | Location | Access to PHI | |---|---|---|---| | Salesforce, Inc. | Platform (compute + storage of the package) | USA, EU, AU regional pods (Controller's choice) | Yes — under Salesforce's standard BAA where Controller requests it | | Vercel Inc. | Hosting of the Next.js portal (stateless, no PHI persistence) | Global edge | No | | Itsme (Belgian Mobile ID NV) | OIDC identity verification for Belgian Data Subjects | Belgium | Identity attributes only | | Supabase Inc. | Email + magic-link authentication for US Data Subjects | USA | Email + session metadata only | | Anthropic, PBC | AI inference for the Jean-Claude chatbot | USA, enterprise no-retention terms | De-identified prompt context only — never PHI |

    5.2 New Subprocessors

    Processor shall give Controller thirty (30) days' prior written notice of any intended addition or replacement of a Subprocessor that has access to PHI or Special Category Data, by updating the Subprocessor List and notifying Controller's designated contact email. Controller may object to such addition on reasonable data-protection grounds within fifteen (15) days of notice. If the Parties cannot agree on a resolution, Controller may terminate the relevant portion of the EULA without penalty.

    5.3 Subprocessor obligations

    Processor shall impose on each Subprocessor by written contract data-protection obligations no less protective than those set out in this DPA, and shall remain fully liable to Controller for the performance of each Subprocessor's obligations.

    6. Data Subject rights

    Processor shall, taking into account the nature of the Processing, assist Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling Controller's obligation to respond to requests for exercising Data Subject rights under applicable law (rights of access, rectification, erasure, restriction of Processing, data portability, objection, withdrawal of consent, and complaint to a supervisory authority).

    Specifically, Processor exposes:

    (a) the anonymization scheduler (SPR_AnonymizationScheduler) executing daily at 02:00 UTC, applying HIPAA Safe Harbor (US) or GDPR pseudonymization (EU/UK/CH/Quebec/Belgium) according to jurisdiction-specific retention rules configured in SPR_Disease__mdt.Anonymization_Days__c; (b) the immutable anonymization ledger SPR_AnonymizationLog__c for audit; (c) the right-to-erasure flow allowing Controller authorized users to trigger immediate pseudonymization on Data Subject request; (d) capability-token revocation for citizen-portal access tokens (HC-XXXX, UN-XXXX).

    If a Data Subject submits a request directly to Processor, Processor shall promptly forward it to Controller and shall not respond to the request unless authorized to do so.

    7. Personal Data Breach

    Processor shall notify Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Controller's Personal Data. The notification shall:

    (a) describe the nature of the Breach including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned; (b) communicate the name and contact details of the Processor's Data Protection Officer or other point of contact; (c) describe the likely consequences of the Breach; (d) describe the measures taken or proposed to address the Breach, including measures to mitigate its possible adverse effects.

    For Breaches affecting PHI of US Subscribers, the timing and content of the notification shall additionally comply with 45 C.F.R. § 164.410 (HIPAA Breach Notification Rule for Business Associates).

    Processor maintains a documented incident-response runbook including evidence preservation, root-cause analysis, and post-incident review.

    8. Data Protection Impact Assessment

    Processor shall provide reasonable assistance to Controller in carrying out Data Protection Impact Assessments (Article 35 GDPR) and prior consultations with supervisory authorities (Article 36 GDPR), where applicable to the Processing of Personal Data under this DPA.

    9. International transfers

    Where Personal Data is transferred outside the European Economic Area, the United Kingdom, or Switzerland to a country not benefiting from an adequacy decision, the Parties incorporate the European Commission's Standard Contractual Clauses adopted by Decision 2021/914 of 4 June 2021 (the "SCCs") in their entirety, with the following selections:

    • Module Two (Controller to Processor) applies for direct Processor relationships;
    • Module Three (Processor to Processor) applies between Processor and PHI/EU-data Subprocessors;
    • Docking Clause 7 is OPTED IN;
    • Clause 9 "General written authorisation" with 30 days' prior notice (Option 2) applies;
    • Clause 11 independent dispute-resolution body is NOT selected;
    • Clause 17 governing law is the law of the EU Member State in which Controller is established (or, failing that, Ireland);
    • Clause 18 forum is the courts of Controller's EU Member State (or, failing that, Ireland);
    • Annex I is populated by reference to Section 2.3 of this DPA;
    • Annex II is populated by reference to Section 4 of this DPA;
    • Annex III is populated by the current Subprocessor List.

    For transfers from the UK, the UK Addendum issued by the Information Commissioner's Office under section 119A of the Data Protection Act 2018 applies. For transfers from Switzerland, the SCCs are read with the adaptations published by the FDPIC.

    For transfers from Quebec to outside Quebec, Processor and Controller cooperate in conducting a privacy-impact assessment compliant with Article 17 of Law 25 and document the equivalence of protections.

    10. Audit rights

    Processor shall make available to Controller all information necessary to demonstrate compliance with this DPA and shall allow for, and contribute to, audits — including inspections — conducted by Controller or another auditor mandated by Controller, no more than once per twelve (12) month period except in case of a Personal Data Breach or as required by a supervisory authority. Audits shall be conducted on at least thirty (30) days' prior written notice, during normal business hours, in a manner that does not unreasonably interfere with Processor's business, and at Controller's expense (except where the audit identifies material non-compliance, in which case reasonable audit costs are borne by Processor). Audit reports are Processor's Confidential Information.

    In lieu of a Controller-led audit, Processor may provide an independent third-party audit report (e.g., SOC 2 Type II) covering substantially the same scope.

    11. Return and deletion

    Upon termination of the EULA or this DPA, Processor shall, at Controller's option exercised within thirty (30) days of termination, return or delete all Personal Data Processed on Controller's behalf, save to the extent that applicable law requires storage of the Personal Data, in which case Processor shall continue to apply this DPA's protections for as long as it retains the Personal Data. Anonymization log entries (SPR_AnonymizationLog__c) and aggregate cluster records that contain no Personal Data are retained for the life of the package.

    12. Liability

    Each Party's liability under this DPA is subject to the limitation of liability provisions in the EULA. Where mandatory data-protection law imposes joint and several liability towards Data Subjects (notably Article 82 GDPR), the Party that has paid full compensation shall be entitled to claim back from the other Party that part of the compensation corresponding to its part of responsibility for the damage.

    13. Order of precedence

    In case of conflict between this DPA and:

    • the BAA — the BAA prevails with respect to PHI;
    • the SCCs — the SCCs prevail with respect to international transfers from the EEA/UK/Switzerland;
    • the EULA — this DPA prevails with respect to Processing of Personal Data;
    • the Privacy Policy — this DPA prevails between the Parties as to their respective obligations.

    14. Term, termination, and survival

    This DPA enters into force on the Effective Date and continues until termination of the EULA. Sections 3, 4 (to the extent applicable to retained data), 7, 10, 11, 12, and 13 survive termination.

    15. Governing law

    This DPA is governed by the laws of the State of Nevada, USA, except that to the extent the GDPR, Law 25, or Belgian Data Protection Act mandates a different governing law, that mandatory law applies. The SCCs in Section 9 retain their own governing-law selection.

    16. Contact

    apphero Tech LLC — Data Protection Officer Las Vegas, Nevada, USA Email: dpo@apphero.tech HIPAA / BAA inquiries: hipaa@apphero.tech Security incidents: security@apphero.tech (24/7 monitored)

    For EU/UK/Swiss Data Subjects, an EU representative will be designated when required under Article 27 GDPR; details will be published on the Subprocessor List page when applicable.


    Annex I — Subject matter and details of Processing

    See Section 2.3 above.

    Annex II — Technical and organizational measures

    See Section 4 above and the more detailed description at https://apphero.tech/spread/security.

    Annex III — Authorized Subprocessors

    See Section 5.1 above and the live Subprocessor List at https://apphero.tech/spread/legal/subprocessors.


    A French version of this DPA is available at https://apphero.tech/spread/fr/legal/dpa. In case of conflict between the two versions, the English version prevails.