Effective Date: January 3, 2026
Company: SomniCharts Inc.
Registered in: Canada
This Enterprise Compliance Addendum ("Addendum") supplements the SomniCharts Terms of Service and applies to enterprise, clinic, healthcare provider, and institutional customers ("Customer").
Part I — Data Processing Agreement (GDPR / PIPEDA)
1. Roles of the Parties
For purposes of applicable data protection laws:
- The Customer acts as Data Controller of patient or end-user personal data.
- SomniCharts acts as Data Processor, processing personal data solely on documented instructions of the Customer.
SomniCharts does not independently determine purposes or means of processing patient data.
2. Nature & Purpose of Processing
Processing activities include:
- Secure storage of uploaded sleep therapy data
- Automated analysis and visualization
- Session-based decryption for authenticated display
- Automatic deletion upon membership termination
Processing is limited to functionality necessary to deliver the SomniCharts platform.
3. Categories of Data
- Sleep therapy data (e.g., CPAP metrics)
- Usage statistics related to therapy compliance
- Limited account identifiers (name, email)
Sensitive health-related data is processed only as uploaded by the Customer.
4. Security Measures
SomniCharts implements:
- Encrypted storage (minimum 128-bit encryption or stronger)
- Encrypted transmission (HTTPS/TLS)
- Logical user isolation via authenticated accounts
- Role-based internal access controls
- No routine employee access to decrypted patient data
- Automatic deletion upon account termination
5. Subprocessors
SomniCharts may engage third-party subprocessors for:
- Cloud infrastructure
- Payment processing
- Email delivery
All subprocessors are contractually obligated to implement appropriate security safeguards.
6. International Transfers
Where personal data is transferred outside the EEA/UK, SomniCharts relies on:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Equivalent lawful safeguards
7. Data Subject Rights
SomniCharts will assist Customer, where reasonably possible, in responding to:
- Access requests
- Deletion requests
- Correction requests
- Restriction or portability requests
8. Data Retention & Deletion
Upon termination or expiration of Customer's membership:
- All patient sleep data is permanently deleted within a commercially reasonable timeframe.
- No archival copies are retained.
- Re-registration requires new data upload.
Part II — HIPAA Business Associate Addendum (BAA)
This section applies only when Customer is a U.S. Covered Entity or Business Associate under HIPAA.
1. Definitions
Terms such as "Protected Health Information (PHI)," "Covered Entity," and "Business Associate" have the meanings assigned under HIPAA (45 CFR Parts 160 and 164).
2. Permitted Uses & Disclosures
SomniCharts may:
- Use PHI solely to provide automated analytics and visualization services.
- Not use PHI for marketing or resale.
- Not disclose PHI except as required to provide services or as required by law.
3. Safeguards
SomniCharts agrees to:
- Implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule.
- Maintain encrypted storage and transmission protections.
- Limit workforce access to PHI.
- Maintain logical account isolation.
4. No Routine Human Review
PHI processed within SomniCharts is handled automatically by the system.
SomniCharts personnel do not routinely access or review PHI except:
- For authorized troubleshooting,
- As required by law,
- Or as requested by Customer.
5. Breach Notification
SomniCharts will notify Customer without unreasonable delay upon discovery of a confirmed breach of unsecured PHI, consistent with HIPAA requirements.
6. Subcontractors
SomniCharts will ensure that subcontractors who may access PHI agree to similar HIPAA-compliant restrictions and safeguards.
7. Term & Termination
This Addendum remains in effect for the duration of the Customer's enterprise agreement.
Upon termination:
- PHI is permanently deleted.
- No retention archives are maintained.
- Deletion occurs within a commercially reasonable timeframe.
Limitation of Liability
This Addendum is subject to the liability limitations set forth in the SomniCharts Terms of Service unless otherwise agreed in writing.
Order of Precedence
In the event of conflict between this Addendum and the Terms of Service, this Addendum shall control with respect to data protection and HIPAA compliance matters.
For enterprise agreements and BAA execution, contact:
admin@somnicharts.com