Overview
FaceofMind offers a Data Processing Agreement (DPA) to business, clinic, and enterprise customers who process personal data through our platform. This DPA is designed to support customers' compliance obligations under the EU General Data Protection Regulation (GDPR), applicable healthcare privacy laws including HIPAA, and the Philippine Data Privacy Act of 2012 (RA 10173).
👤1. Roles & Responsibilities
You (hospital, clinic, employer group, or practice). You define the processing purpose, patient permissions, and clinical workflows.
FaceofMind. We process patient wellness logs, mood reports, voice clips, and journal sentiment parameters strictly as directed in the service agreement.
2. Security & Technical Safeguards
FaceofMind implements appropriate technical and organizational measures (TOMs), including encryption at rest and in transit, key management, access controls, audit logging, and other safeguards appropriate to the risk. For additional details, refer to our Trust Center.
3. Sub-Processors
We utilize the following sub-processors to deliver core components of the platform:
| Processor | Purpose | Region Used |
|---|---|---|
| Google Cloud Platform | Secure data storage, cloud computing, key management | Regions selected per contractual and regulatory requirements |
• FaceofMind provides a 30-day notice prior to onboarding new sub-processors.
• You maintain the right to object to new sub-processor appointments on reasonable security or privacy grounds.
4. Data Retention & Deletion Schedule
| Data Type | Retention Limit | Deletion Process |
|---|---|---|
| Mood logs & Journal metrics | 24 months | Deleted within 30 days of request |
| Voice recordings & Pitch data | 12 months | Deleted within 30 days of request |
| Consultation records | 7 years | Statutory hold, then auto-purged |
| Security audit logs | 24 months | Anonymized and purged |
Upon Contract Termination: All personal data is purged from active systems and database backups within 30 days of service cancellation. Upon request, FaceofMind may provide written confirmation that deletion has been completed, subject to applicable legal and technical limitations.
5. Customer & Data Subject Rights
Customers can request on-demand security audit access and review available security documentation.
We cooperate with user requests for access or correction. Data Subject Access Requests (DSARs) are handled and exported in structured JSON/CSV formats within 10 business days.
Provides clear visibility of user data accesses via immutable audit logs, showing who inspected which files and when.
Purging triggers immediately upon customer request, with full verification provided within the 30-day timeline.
6. Breach Notification & Response
In the event of a security incident affecting patient details:
• Investigation: Discovered incidents are isolated and investigated promptly and without undue delay.
• Customer Notification: FaceofMind will notify the Customer without undue delay and in any event within 72 hours of becoming aware of a confirmed breach, where required by applicable law.
• Regulatory Reporting: Incident metrics are reported to regulatory authorities (NPC, DPAs) as legally required.
• Remediation: Post-incident reports and mitigation steps will be shared with affected customers in a timely manner.
7. Regional Data Transfers
Data is processed in regions selected to meet applicable contractual, regulatory, and operational requirements. Specific regional commitments are documented in each customer's executed DPA.
Where personal data is transferred across borders, FaceofMind relies on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms as required by GDPR Articles 44–50 and applicable local law. For US healthcare customers, Business Associate Agreements (BAAs) are executed with infrastructure partners where applicable.
🤝8. Cooperation & Response Plan
Both parties commit to joint coordination regarding privacy concerns. If you suspect an access breach or regulatory audit request, our security team will coordinate investigative findings and construct mitigation resolutions together.
9. How to Request Our DPA
To initiate a Data Processing Agreement for an active or planned clinic or health system deployment:
1. Email Request: Send an inquiry to legal@faceofmind.com.
2. Details to Include: Your organization name, intended use case, regulatory jurisdiction (US, EU, PH), and procurement timeline.
3. Review Process: Standard DPA agreements are sent immediately. Complex custom adjustments are completed within 10 business days.
⚙️10. DPA Customization
Our standard DPA covers standard regulatory requirements under GDPR, HIPAA, and RA 10173. If your legal counsel requires specific liability amendments, custom insurance clauses, or custom sub-processor notice timelines, we are open to negotiate custom addendums.