Data Processing Addendum
Last updated: July 13, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between R2 Technologies LLC, a California limited liability company operating the Pairity platform (“Pairity,” “we,” “us”), and the customer organization named on the applicable Order Form or Master Subscription Agreement (“Customer,” and together the “Agreement”). It describes how we process personal information on Customer's behalf in the course of providing the Pairity platform.
Where we process protected health information (“PHI”) for Customer, the Business Associate Agreement (“BAA”) between the parties governs that PHI, and the BAA controls over this DPA to the extent of any conflict.
1. Roles
Customer determines the purposes and means of processing the personal information it enters into the platform, and we process it only on Customer's behalf and under Customer's instructions. Under U.S. state privacy laws, we act as Customer's “service provider” or “processor”; under HIPAA, we act as Customer's business associate.
2. Scope and details of processing
- Subject matter and duration. Processing of Customer Data to provide the platform for the term of the Agreement, plus the return-and-deletion period described in Section 8.
- Nature and purpose. Hosting, storage, transmission, and display of Customer Data to operate scheduling, client records, authorizations, hiring and onboarding, billing, and related notifications and support.
- Categories of individuals. Customer's staff, candidates, and clients and their caregivers.
- Categories of data. Names and contact details, employment and credentialing records, schedules and coverage, service authorizations, insurance and billing information, and — where Customer uses clinical features — PHI, which is governed by the BAA.
3. Our obligations
We will:
- process Customer Data only to provide the service and as documented in the Agreement, this DPA, and Customer's reasonable written instructions — not for our own purposes;
- not sell Customer Data, share it for cross-context behavioral advertising, or use it for advertising of any kind;
- ensure that personnel authorized to process Customer Data are bound by confidentiality obligations;
- notify Customer if we determine we can no longer meet our obligations under applicable privacy law, and allow Customer to take reasonable steps to stop and remediate unauthorized use.
4. Security
We maintain administrative, technical, and physical safeguards designed to protect Customer Data, including:
- encryption of data in transit and at rest;
- role-based access controls and audit logging;
- infrastructure isolation on HIPAA-eligible Amazon Web Services infrastructure under a signed BAA with AWS;
- access to Customer Data within Pairity limited to what is needed to operate and support the service.
5. Subprocessors
Customer authorizes us to engage subprocessors to help provide the service — currently cloud hosting (Amazon Web Services) and transactional email delivery. We contractually require subprocessors to protect Customer Data to a standard no less protective than this DPA, and we remain responsible for their performance. We will give Customer notice of any new subprocessor that will process Customer Data, and Customer may object on reasonable data-protection grounds; if we cannot resolve the objection, Customer may terminate the affected service.
6. Security incidents
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data, we will notify Customer without undue delay, provide information reasonably available to us about the incident, and take reasonable steps to contain and remediate it. Notification of incidents involving PHI follows the timelines in the BAA.
7. Assistance
Taking into account the nature of the processing, we will reasonably assist Customer in responding to requests from individuals to exercise their privacy rights (access, correction, deletion), and in meeting Customer's obligations regarding security, incident notification, and privacy assessments. If we receive a request directly from an individual whose data Customer controls, we will direct them to Customer, as described in our Privacy Policy.
8. Return and deletion
During the term, Customer can export its data from the platform. Upon termination or expiration of the Agreement, we will make Customer Data available for export for thirty (30) days, then delete it from active systems, except where retention is required by law. Data governed by the BAA is returned or destroyed as the BAA provides.
9. Audits
Upon reasonable written request, no more than once per year, we will make available information reasonably necessary to demonstrate compliance with this DPA — such as security documentation and summaries of third-party assessments — and will reasonably cooperate with audits required of Customer by law or regulators, subject to confidentiality and reasonable scheduling.
10. Data location
Customer Data is hosted in the United States. We will not transfer Customer Data outside the United States without Customer's prior consent.
11. Precedence and term
This DPA takes effect on the effective date of the Agreement and remains in force for as long as we process Customer Data. If this DPA conflicts with the Agreement, this DPA controls as to the processing of personal information; the BAA controls as to PHI.
12. Contact
Questions about this DPA or to request a signed copy: info@pairityaba.com.