Data Processing Agreement
Version 2026-07 · Last updated 26 July 2026
This Data Processing Agreement (“DPA”) governs our processing of personal data on your clinic’s behalf. It forms part of the agreement between your clinic and PhysiPal Pty Ltd trading as Hanah, and applies whenever Hanah handles clinical information belonging to your practice.
At a glance
- You are the controller. Your clinic decides why and how patient data is processed. Hanah acts as your processor and follows your instructions.
- We act only on your instructions. Using Hanah’s features is your instruction to us. We do not process clinical data for our own purposes.
- No training on your content. Neither we nor our AI subprocessors train models on your clinical data.
- Subprocessors are published. The current list for your region is maintained in our Trust Centre, and you get advance notice before it changes.
- You can get your data out, and have it deleted. Export at any time during the term; deletion or return on termination.
- We help you meet your obligations. Patient rights requests, breach notification, and privacy impact assessments.
1. How this agreement applies
This DPA is entered into between:
PhysiPal Pty Ltd (ABN 61 641 678 891), trading as Hanah, of 826/555 Flinders St, Melbourne VIC 3000, Australia (“Hanah”, “we”, “us”); and
the clinic, practice or organisation that accepted this DPA when creating its Hanah workspace (“you”, “your clinic”).
It is accepted by a person with authority to bind your clinic, at the point the workspace is created. Individual clinicians who later join an existing workspace are covered by the acceptance given by the clinic that invited them, and do not accept this DPA separately.
This DPA supplements our Terms, Privacy & Content Policy. Where this DPA and that policy conflict in relation to our processing of clinical data on your behalf, this DPA prevails.
We may update this DPA to reflect changes in law, our services, or our subprocessors. Where a change materially reduces your rights or our obligations, we will give you at least 30 days’ notice and you may terminate before it takes effect. We will not make a change that would put us in breach of applicable data protection law.
2. Definitions
“Data protection law” means the law applicable to your clinic’s region, as set out in Annex D.
“Clinical data” means personal data relating to your patients that we process on your behalf through the services — including consultation audio, transcripts, clinical notes, documents, referrals, patient records and correspondence.
“Controller”, “processor”, “data subject”, “personal data”, “personal data breach” and “processing” have the meanings given in the UK GDPR, and are read as their nearest equivalents under Australian and New Zealand law.
“Subprocessor” means a third party engaged by us to process clinical data on your behalf.
3. Roles and responsibilities
The parties’ roles differ depending on the data in question:
| Data | Controller | Our role |
|---|---|---|
| Clinical data — audio, transcripts, notes, documents, patient records | Your clinic | Processor, acting on your instructions |
| Clinician account data — names, email addresses, authentication credentials, role assignments | Your clinic and Hanah, each for their own purposes | Processor for your workspace administration; controller for account security and service delivery |
| Service operation data — billing records, support correspondence, security and audit logs, aggregate usage statistics | Hanah | Controller |
Where we act as controller, our handling of that data is described in our Terms, Privacy & Content Policy rather than in this DPA.
You remain responsible for the lawfulness of the clinical data you put into the service, for the clinical decisions made using it, and for your professional record-keeping obligations.
4. Scope and duration of processing
We process clinical data only for the duration of your use of the services, plus any period expressly permitted under clause 11 (deletion and return).
The subject matter, nature, purpose, categories of data and categories of data subjects are set out in Annex A.
5. Our obligations as processor
5.1 We act only on your instructions
We process clinical data only on your documented instructions, including in relation to transfers outside your region, unless we are required to do otherwise by law — in which case we will tell you before processing, unless the law prohibits us from doing so.
Your instructions are given by: this DPA; our Terms, Privacy & Content Policy; your and your clinicians’ use of the features of the service; and any configuration you apply to your workspace. Using a feature is an instruction to carry out the processing that feature performs.
If we believe an instruction infringes data protection law, we will tell you and may suspend the affected processing until it is resolved.
If we process clinical data for our own purposes rather than yours, we become a controller in respect of that processing and assume the corresponding responsibilities.
5.2 We do not use your data to improve our models
We do not use clinical data to train, fine-tune or evaluate machine learning models, and our AI subprocessors are contractually prohibited from training on it. We may use aggregated statistics derived from the service — such as counts, timings and error rates — to operate and improve it, provided those statistics do not identify you, your clinicians or any patient and cannot reasonably be used to do so.
5.3 Confidentiality
We ensure that everyone authorised to process clinical data is subject to an appropriate duty of confidentiality, and that access is limited to those who need it to deliver, support or secure the service.
5.4 Security
We implement appropriate technical and organisational measures to protect clinical data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, and the risk to patients. A summary is in Annex B.
5.5 Subprocessors
You give us general authorisation to engage subprocessors. The current list for your region is published in our Trust Centre — see Annex C.
Before a new subprocessor begins processing clinical data, we will give you at least 30 days’ notice. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected services without penalty and receive a pro-rata refund of any prepaid fees.
We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
5.6 Assisting with patient rights requests
Patients exercise their rights against you, as controller. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests for access, rectification, erasure, restriction, portability and objection.
The service provides self-service export and deletion for the data your clinic holds, which will usually be sufficient. Where it is not, we will provide reasonable additional assistance in time for you to meet your statutory deadline.
If a patient contacts us directly about data we hold on your behalf, we will not respond substantively. We will tell them to contact their clinic and, where we can identify you, forward the request to you without undue delay.
5.7 Assisting with security, breaches and impact assessments
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations relating to security of processing, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
5.8 Audit and information
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by you or an auditor you appoint.
In the first instance we will respond to reasonable written questions and provide the material published in our Trust Centre and our Security & Operations Handbook. Where that is not sufficient for your regulatory obligations, we will cooperate with an on-site or remote audit on reasonable notice, no more than once in any 12-month period unless required by a regulator or following a personal data breach. Audits must be conducted during business hours, must not unreasonably disrupt the service, and are subject to confidentiality. Each party bears its own costs.
6. Personal data breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting clinical data we process for you.
Our notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where the full picture is not available at once, we will provide information in phases as it becomes available.
We will not notify a supervisory authority or affected patients on your behalf unless you instruct us to, or we are independently required to do so.
7. International transfers
We process clinical data in your region except where set out in our Terms, Privacy & Content Policy and in the regional subprocessor lists. Current cross-border processing is summarised in Annex D.
Where we transfer clinical data outside your region, we do so only under a transfer mechanism valid under your region’s data protection law, and we maintain the safeguards required by it. We will not introduce a new cross-border transfer of clinical data without giving you notice under clause 5.5.
8. Your obligations
You warrant that:
- you have a lawful basis for the clinical data you process through the service, and for special category or sensitive health information, a valid condition for processing it;
- you have provided patients with the information required by data protection law about how their data is handled, including the use of AI-assisted documentation and ambient transcription;
- where you use ambient transcription, you have obtained patient consent to being recorded before recording begins;
- your instructions to us comply with data protection law; and
- you will not put into the service any personal data that is outside the categories described in Annex A.
You are responsible for configuring your workspace appropriately, managing who has access to it, and reviewing AI-generated output before relying on it clinically or sending it to a third-party system.
9. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the agreement between us, except that nothing in this DPA or that agreement limits either party’s liability to a data subject or a supervisory authority under data protection law.
10. Term and termination
This DPA takes effect when you accept it and continues for as long as we process clinical data on your behalf. Clauses that by their nature should survive termination do so, including confidentiality, deletion and return, and liability.
11. Deletion and return
You may export your clinical data at any time during the term using the service’s export functions.
On termination, we will, at your choice, delete or return your clinical data. Unless you instruct otherwise within 30 days of termination, we will delete it. Deletion removes clinical data from live systems within 30 days; encrypted backups are purged on their normal rotation cycle, within a further 90 days, during which the data remains subject to this DPA and is not restored except for disaster recovery.
We may retain clinical data where required by law, in which case we will retain only what is required, for only as long as required, and continue to protect it under this DPA.
Your record-keeping remains yours. Clinicians are generally required to retain clinical records for a number of years after the last entry. Deleting your Hanah workspace does not discharge that obligation, and we do not retain records on your behalf after deletion. Export before you terminate.
12. Governing law
The governing law and jurisdiction for this DPA are those set out for your region in Annex D.
Annex A — Details of the processing
Subject matter
Provision of the Hanah platform: AI-assisted clinical documentation, ambient transcription, patient records, document generation, messaging, and integration with practice management systems.
Duration
The term of your use of the services, plus the deletion periods in clause 11.
Nature and purpose
Collection, recording, transcription, organisation, storage, retrieval, analysis, generation of draft clinical documentation, transmission to systems you nominate, and deletion.
Categories of personal data
- Health information — symptoms, history, examination findings, diagnoses, treatment plans, progress, referrals and correspondence.
- Consultation audio and transcripts — where ambient transcription is used.
- Patient identifiers — name, contact details, and identifiers assigned by you or your practice management system.
- Clinician data — name, email address, professional role and workspace permissions.
- Files — documents and images uploaded to a patient record.
Categories of data subjects
- Your patients, including where relevant their parents or guardians.
- Your clinicians, administrators and other workspace users.
- Third parties named in clinical correspondence, such as referring practitioners.
Special category / sensitive data
The processing involves health data, which is special category personal data under UK GDPR Article 9 and sensitive information under the Australian Privacy Act and the New Zealand Health Information Privacy Code.
Annex B — Technical and organisational measures
We maintain measures including:
- Regional isolation — each region runs on separate infrastructure with its own database and object storage, so clinical data does not commingle across regions.
- Encryption — in transit over TLS, and at rest for databases, object storage and backups.
- Tenant isolation — database row-level security enforced at the database, so a request authenticated for one clinic cannot read another’s records.
- Least privilege — separate database roles for application request paths, with no direct table access beyond what each role requires.
- Access control — authenticated access with role-based permissions; administrative access restricted and separately authenticated.
- Audit logging — append-only logs of administrative and privileged actions, retained and monitored centrally.
- Transient AI processing — audio and text sent to AI subprocessors are processed transiently and not retained by them; raw audio is deleted once the transcript is produced.
- Backups — encrypted, region-resident backups with defined restoration procedures.
- Secrets management — infrastructure credentials held in an encrypted vault with access recorded.
A control-by-control description, including how each is implemented, is published in the Controls section of the Trust Centre for your region (see Annex C). Further evidence is available under NDA.
Annex C — Subprocessors
The current subprocessor list for each region — naming the provider, its function, the data it handles, and where it processes that data — is published and maintained here:
These pages are the authoritative list for the purposes of clause 5.5. To be notified of changes, or to receive a point-in-time copy, contact hello@hanah.health.
Annex D — Regional terms
United Kingdom
Applicable law: UK GDPR and the Data Protection Act 2018. This DPA is intended to satisfy Article 28(3).
Health data condition: we process health data as your processor under Article 9(2)(h) (provision of health care), relying on your condition as controller, and maintain an appropriate policy document where required under Schedule 1 of the Data Protection Act 2018.
Cross-border processing: AI drafting and speech-to-text for UK clinics are performed in the United Kingdom. Limited account and authentication data may be processed outside the UK; where that occurs we rely on the UK Addendum to the Standard Contractual Clauses.
Supervisory authority: the Information Commissioner’s Office.
UK representative: appointed under Article 27 — Saad Sami, 3 old highwayman place, London SW15 4BF, saad@hanah.health.
Governing law: England and Wales.
Australia
Applicable law: the Privacy Act 1988 (Cth) and the Australian Privacy Principles, together with applicable state health records legislation.
Cross-border processing: AI drafting and storage for Australian clinics are performed in Australia. Ambient audio is transmitted to our speech-to-text subprocessor in the United States for transcription and is not retained after the transcript is produced; the transcript is stored in Australia. This is a cross-border disclosure for the purposes of APP 8, and we take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles.
Breach notification: we support your obligations under the Notifiable Data Breaches scheme, including the 30-day assessment period.
Supervisory authority: the Office of the Australian Information Commissioner.
Governing law: Victoria, Australia.
New Zealand
Applicable law: the Privacy Act 2020 and the Health Information Privacy Code 2020.
Holding of information: information we hold as your service provider is treated as held by your clinic under section 11 of the Privacy Act 2020.
Cross-border processing: clinical records for New Zealand clinics are stored in New Zealand. Ambient audio and clinical text are processed in Australia for speech-to-text and AI drafting, and the results are returned to New Zealand for storage. This is a cross-border disclosure for the purposes of IPP 12, and we rely on contractual safeguards requiring recipients to protect the information to a standard comparable to that required under New Zealand law.
Supervisory authority: the Office of the Privacy Commissioner.
Governing law: New Zealand.
Contact
Questions about this DPA, subprocessor notifications, audit requests and breach correspondence:
Email: hello@hanah.health
Post: PhysiPal Pty Ltd, 826/555 Flinders St, Melbourne VIC 3000, Australia