Spread — Legal

    Privacy Policy

    How Spread handles personal data, PHI, and Special Category Data across GDPR, HIPAA, Law 25, and Belgian law.

    Last updated
    June 1, 2026
    Version
    v1.0.0

    Privacy Policy — Spread

    Effective date: June 1, 2026

    This Privacy Policy describes how apphero Tech LLC, a Nevada limited liability company based in Las Vegas, Nevada, USA ("apphero", "we", "us", "our"), collects, uses, discloses, and protects personal data in connection with the Spread managed package on the Salesforce AppExchange and the Spread public, professional, and agency portals (collectively, the "Service").

    Spread processes special-category personal data — including health, disease-status, and other Protected Health Information ("PHI"). The protections set out in this Policy supplement, and do not replace, the safeguards required by the EU/UK General Data Protection Regulation ("GDPR"), the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the HITECH Act, Quebec's Law 25, Belgium's data protection law (the Belgian Privacy Act and the Cooperation Agreement on the Belgian eHealth Platform), and any equivalent regulation that applies to a particular deployment.

    This Policy applies to:

    • Subscribers: public-health authorities, hospitals, school districts, universities, and other organizations that install Spread in their Salesforce org;
    • Authorized users: employees, contractors, agents, and volunteers of Subscribers using Spread;
    • Citizens: members of the public who use the Spread citizen portal to declare symptoms, track a health concern, subscribe to alerts, or consult vaccination centers;
    • Health professionals: doctors, nurses, lab technicians, hospital staff, care-home managers, and school nurses who use the Spread professional portal to declare cases;
    • Visitors: anyone visiting our public marketing site at apphero.tech/spread.

    1. Roles under data protection law

    For data processed within a Subscriber's Salesforce org, the Subscriber is the data controller (and, under HIPAA, the Covered Entity) and apphero acts as a data processor (and, under HIPAA, a Business Associate). The Data Processing Agreement (DPA) and, where required, the Business Associate Agreement (BAA) govern that processing.

    For data processed through the apphero-operated Spread portal layer (Next.js) and our marketing site, apphero is the data controller.

    For inquiries regarding our role as data processor / Business Associate, contact your relevant public-health authority or hospital directly. For inquiries regarding apphero as controller, contact us at the address in Section 12.

    2. Data we collect

    2.1 Subscriber and authorized-user data

    When a Subscriber installs Spread, we receive Salesforce org metadata (org ID, instance, package version), limited admin contact information, and license-management telemetry needed to administer the subscription. We do not access Subscriber data within the org except as required for support, with the Subscriber's written or audit-logged permission, or as set forth in the DPA/BAA.

    2.2 Citizen data (via the public portal)

    When citizens use the Spread citizen portal to declare a health concern, track a declaration, subscribe to alerts, or consult vaccination information, we collect:

    • Identity: first name, last name, date of birth, email address, phone number (optional);
    • Jurisdiction identifiers: postal code, commune/county/region, country (jurisdiction code such as BE_REGION, US_STATE, CA_PROVINCE, FR_REGION);
    • Jurisdiction-aware patient identifiers: in Belgium, the NISS/BIS national identification number (collected via Itsme eID, never typed by the citizen); in the United States, a SHA-256 hash of last name + date of birth used for de-duplication only — no national identifier is collected;
    • Health concern: suspected disease, symptom description, suspected onset date, exposure context, free-text notes;
    • Capability tokens: an opaque tracking token (HC-XXXX) returned to the declarant so they can later track the status of their declaration without re-identifying;
    • Subscriber data: for alert subscribers, the postal code, commune, language preference, and an unsubscribe token (UN-XXXX);
    • Authentication artifacts: OIDC id_token from Itsme (Belgium) or magic-link session from Supabase (US) — these are exchanged for a short-lived Salesforce access token and not persisted in the portal;
    • Device and usage data: IP address (truncated where possible), browser type, device identifiers, timestamps, referral source. We do not use third-party advertising trackers.

    2.3 Health-professional data

    When health professionals authenticate and declare cases:

    • Identity: full name, professional email, organization (hospital, lab, school, care home), role;
    • License/accreditation: professional ID (e.g., NPI in the US — Phase 2; INAMI/RIZIV in Belgium);
    • Case data: disease, clinical status, ICD-10 code, lab confirmation status, exposure history, patient demographics — collected on behalf of the Subscriber as Business Associate;
    • Audit trail: action log per case, time stamps, IP address.

    2.4 Agency-user data

    When agency staff (epidemiologists, investigators, public-health officers) use the Spread Lightning app inside their Subscriber org, the data they access is governed by their Subscriber's Salesforce policies. apphero does not see this data except for break-fix support with explicit subscriber consent and an audit trail.

    2.5 Visitor data

    On apphero.tech/spread, we collect technical data via cookies and similar technologies (see our Cookie Policy) and any information you submit via contact forms.

    3. How we use data

    We process personal data — including PHI and other Special Category Data — to:

    (a) provide and operate the Service, including symptom declarations, case management, contact tracing, cluster detection, vaccination management, and public-health communication; (b) generate and validate capability tokens that allow citizens to track their own declarations without account creation; (c) anonymize and aggregate data after the regulatory retention period, in accordance with HIPAA Safe Harbor (US) or GDPR pseudonymization with right-to-erasure (EU/UK/CH/Quebec/Belgium); (d) detect, prevent, and respond to fraud, abuse, security incidents, and reportable disease outbreaks; (e) provide customer support to Subscribers and authorized users; (f) improve and develop the Service, using only de-identified or aggregated data — no PHI is used to train AI models or to develop new features; (g) comply with mandatory disease-notification obligations on behalf of Subscribers (e.g., Sciensano in Belgium, CDC NEDSS in the US), strictly as a Business Associate / data processor acting on the Subscriber's documented instructions; (h) send transactional communications (declaration confirmations, alert subscriptions, vaccination reminders); (i) comply with legal obligations and enforce our agreements.

    We do not sell, rent, or barter personal data. We do not use PHI for any form of advertising, profiling, or commercial targeting.

    4. Legal bases (GDPR / Law 25 / Belgian Privacy Act)

    Where the GDPR, Quebec's Law 25, or equivalent law applies, we rely on the following legal bases:

    • Performance of a contract or pre-contractual measures: to provide the Service to declarants and alert subscribers;
    • Public interest in the area of public health (Article 9(2)(i) GDPR): for the processing of health data by Subscriber public-health authorities and Business Associates acting on their behalf, including reporting obligations under national disease-surveillance frameworks;
    • Vital interests (Article 9(2)(c) GDPR): when contact tracing is necessary to protect the life of an exposed individual;
    • Explicit consent (Article 9(2)(a) GDPR): for voluntary alert subscriptions and optional disclosures beyond what surveillance regulation requires;
    • Legitimate interests: to secure the Service, prevent abuse, and improve features (balanced against your rights, never overriding Article 9 protections);
    • Legal obligation: to comply with mandatory reporting, tax, accounting, and regulatory requirements.

    Where we process special-category data under Article 9 GDPR, we implement appropriate safeguards including encryption, access controls, pseudonymization where compatible with purpose, and contractual confidentiality undertakings.

    5. HIPAA disclosures (United States)

    For US Subscribers that are Covered Entities under HIPAA, apphero acts as a Business Associate and is bound by a Business Associate Agreement (BAA) that supplements this Policy. In summary, we:

    • use and disclose PHI only as permitted by the BAA and the HIPAA Privacy Rule;
    • implement administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 C.F.R. §§ 164.308–164.312);
    • report security incidents and breaches in accordance with the HIPAA Breach Notification Rule (45 C.F.R. § 164.410);
    • ensure that our subprocessors who access PHI are bound by equivalent contractual protections;
    • apply Safe Harbor de-identification (45 C.F.R. § 164.514(b)(2)) when anonymizing records past their retention period.

    This Policy does not modify the BAA. In case of conflict between this Policy and the BAA with respect to PHI, the BAA prevails.

    6. Sharing and subprocessors

    We share personal data only with:

    • Subprocessors providing infrastructure, authentication, communication, and AI services on our behalf. The current list of subprocessors for Spread is published and maintained at https://apphero.tech/spread/legal/subprocessors and currently includes:

    | Subprocessor | Purpose | Location | PHI access | |---|---|---|---| | Salesforce, Inc. | Platform (compute + storage of the package) | USA + EU + AU regional pods | Yes — under Salesforce's standard BAA where Subscriber requests it | | Vercel Inc. | Hosting of the Next.js portal (stateless, no PHI persistence) | Global edge | No — portal does not persist PHI | | Itsme (Belgian Mobile ID NV) | OIDC identity verification for Belgian citizens and pros | Belgium | Identity attributes only | | Supabase Inc. | Email + magic-link authentication for US users | USA | Email + session metadata only | | Anthropic, PBC | AI inference for the Jean-Claude chatbot | USA, enterprise no-retention terms | De-identified prompt context only — never PHI |

    Subprocessors that access PHI are bound by equivalent confidentiality and security obligations and are listed in the BAA. We give Subscribers thirty (30) days' prior notice of any new subprocessor that would access PHI and the right to object.

    • Subscribers (data controllers), who receive data related to their own jurisdiction's surveillance operations.
    • Legal recipients when required by law, court order, or to protect rights, safety, and property — restricted to the minimum necessary.
    • Successors in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.

    We do not sell or share PHI for any non-public-health purpose.

    7. International transfers

    Personal data may be transferred to and processed in the United States and other countries where we or our subprocessors operate. For transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs, 2021 version) and additional safeguards (including, where appropriate, supplementary measures consistent with the Schrems II ruling — encryption at rest with subscriber-controlled keys, contractual no-access undertakings for support personnel). PHI subject to HIPAA remains in the United States or in regions covered by the Subscriber's BAA arrangements.

    For transfers from Quebec to outside Quebec, we conduct a Privacy Impact Assessment (PIA) consistent with Article 17 of Law 25 and document the equivalence of protections.

    8. Retention

    We retain personal data only as long as necessary for the purposes described in this Policy or as required by law:

    | Data category | Retention period | |---|---| | Active health concern (citizen-declared) | Until clinical resolution + the Disease-specific Anonymization_Days (typically 90 days post-closure for non-mandatory-notifiable diseases) | | Confirmed mandatory-notifiable disease case | Statutory retention period defined by the Subscriber's national regulator (e.g., 10 years for Sciensano in Belgium; per state/county requirements in the US) — then anonymized | | Cluster records (aggregate) | Indefinite (epidemiological value); records contain no direct identifiers | | Capability tokens (HC-XXXX, UN-XXXX, public-access magic-link tokens) | 30 minutes (magic links) to lifetime of the related record (tracking tokens) — hashed in storage | | Active citizen alert subscription | Duration of the subscription | | Inactive citizen alert subscription | 24 months from last activity, then deleted or anonymized | | Authentication artifacts (Itsme, Supabase session tokens) | Session duration only; never persisted server-side | | Audit and security logs | 90 days (longer where required by HIPAA § 164.312(b), GDPR Article 30, or the Subscriber's BAA) | | Anonymization log (SPR_AnonymizationLog__c) | Immutable — retained for the life of the package, contains no personal data | | Legal and tax records | As required by applicable law |

    After the retention period, data is anonymized in accordance with HIPAA Safe Harbor (US) or pseudonymized + erased on request (EU/UK/CH/Quebec/Belgium) and never reconstituted.

    9. Security

    We implement technical and organizational measures including:

    • Encryption in transit (TLS 1.2+) for all communication
    • Encryption at rest (AES-256, native to Salesforce; AES-256 on Vercel-managed secrets)
    • Access controls via Permission Sets shipped with the package — least privilege per persona (Citizen, Health Pro, Investigator, Officer, Admin)
    • Field-level security enforced manually in Apex code at every public entry point via the SPR_SecurityUtils helper
    • Audit logging of every anonymization and every login-as-subscriber-user event by apphero support
    • Vulnerability management including a continuous integration pipeline that runs the Salesforce Code Analyzer on every commit and blocks merges with unresolved security findings
    • Incident response procedures with a documented Breach Notification process aligned with HIPAA (US) and GDPR Article 33 (EU)
    • Subprocessor management with written contractual safeguards and periodic review

    No method of transmission or storage is fully secure; however, we follow industry best practices and our DPA/BAA detail our security commitments.

    10. Your rights

    Depending on your jurisdiction, you may have the right to:

    (a) access and obtain a copy of your personal data; (b) rectify inaccurate or incomplete data; (c) request deletion ("right to be forgotten") — subject to mandatory retention obligations for notifiable-disease records; (d) restrict or object to processing — note that processing under Article 9(2)(i) GDPR (public interest in public health) cannot be objected to under most national laws while a public-health emergency is active; (e) data portability; (f) withdraw consent at any time, where processing relies on consent; (g) lodge a complaint with your data protection authority (e.g., CNIL in France, APD in Belgium, CNPD in Luxembourg, ICO in the UK, CAI in Quebec, your State Attorney General in the U.S., or the U.S. Department of Health and Human Services Office for Civil Rights for HIPAA matters).

    To exercise these rights, contact us at the address in Section 12. For data within a Subscriber's Salesforce org, contact the relevant Subscriber (Covered Entity / controller), who will forward the request to us if needed.

    11. Children

    The Service is designed primarily for adults and for authorized health professionals. Citizens under 16 years of age should not declare a health concern through the public portal in their own name; a parent or legal guardian must do so on their behalf. We do not knowingly collect personal data directly from children under 16 except as part of a declaration made by a parent or guardian, or as part of a school-managed declaration where the Subscriber school district has obtained parental consent in accordance with FERPA (US) or equivalent. If we become aware that we have collected such data without lawful basis, we will delete it.

    12. Cookies and trackers

    Our use of cookies on the Spread portal is described in our Cookie Policy. The public portal uses only strictly necessary cookies and an opt-in language preference cookie. No third-party advertising or analytics trackers are used.

    13. Changes to this Policy

    We may update this Policy from time to time. Material changes will be communicated to Subscribers via email and posted on this page with a revised effective date. Where required by law (notably under HIPAA), changes affecting PHI processing will be subject to a separate Notice of Privacy Practices update issued by the relevant Covered Entity.

    14. Contact

    apphero Tech LLC Las Vegas, Nevada, USA General privacy inquiries: privacy@apphero.tech HIPAA / BAA inquiries: hipaa@apphero.tech Data Protection Officer: dpo@apphero.tech

    For EU/UK/Swiss data subjects, an EU representative will be designated when required under Article 27 GDPR; details will be published on this page when applicable. apphero appoints a designated Data Protection Officer in accordance with Article 37 GDPR given the large-scale processing of special-category data described in this Policy.


    A French version of this Policy is available at https://apphero.tech/spread/fr/legal/privacy. In case of conflict between the two versions, the English version prevails.