health.network Data Processing Addendum (DPA)

Published: September 15, 2026
Last Revised: See Revision History

Incorporated into: health.network Startup Terms of Service — Startup Embeddables and Startup SDK Packages only

This Data Processing Addendum (“DPA” or “Addendum”) is incorporated by reference into the health.network Startup Terms of Service (the “Agreement”) between b.well Connected Health, Inc. (“b.well”) and Customer. Together with the Agreement, the Order Form, and the b.well Acceptable Use Policy (AUP), this DPA constitutes the complete data processing framework governing b.well’s Processing of Personal Data on Customer’s behalf.

This DPA applies wherever b.well Processes Personal Data as a processor or service provider acting on Customer’s instructions. It does not govern b.well’s use of De-Identified Data, AI obligations under ToS Section 6, or data for which b.well acts as an independent controller under Applicable Data Protection Law. Where b.well is required to function as a Customer’s business associate, a Business Associate Addendum may be specified in the Order Form and replaces the terms of this DPA in the Agreement in their entirety.

Capitalized terms not defined in this DPA have the meanings assigned in the Agreement (including Exhibit A — Definitions). In the event of any conflict, this DPA controls over the Agreement with respect to the Processing of Personal Data.

1. Roles and Processing Instructions

Customer is and shall remain the controller of all Personal Data provided to or accessed by b.well under the Agreement. b.well shall act as a processor (or “service provider” under applicable U.S. state privacy law) and shall Process Personal Data only: (a) as necessary to perform its obligations and deliver the Products and Services under the Agreement; (b) in accordance with Customer’s documented instructions; and (c) as required by Applicable Data Protection Law and governing frameworks for the exchange of health information.

Customer’s execution of the Agreement and Order Form constitutes its documented instructions to b.well for Processing. Customer may provide additional written instructions from time to time; b.well will promptly notify Customer if it determines that any instruction violates Applicable Data Protection Law.

The subject matter, nature, purposes, duration, categories of data, and categories of Data Subjects applicable to Processing under this DPA are set forth in Schedule A (Processing Details) at the end of this document.

Excepting internal analyses performed on Customer’s behalf as described in ToS Section 6.1, b.well’s data use rights operating on the basis of b.well’s de-identification of Customer Data and, for AI training within Beta Releases, each Consumer End User’s specific, informed opt-in consent under b.well’s AI Training Consent Notice are separate from, and not limited by, this DPA.

2. Confidentiality of Personal Data

b.well will ensure that all personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations, whether by contract or statutory requirement, and are trained on applicable data protection requirements. b.well will limit access to Personal Data to those personnel who require it to perform the Services.

3. Security

3.1  Information Security Program

b.well will implement and maintain a written Information Security Program comprising administrative, technical, and physical safeguards appropriate to the nature and sensitivity of the Personal Data Processed, including health data. These safeguards are designed to: (a) protect the confidentiality, integrity, and availability of Personal Data; (b) protect against reasonably anticipated threats and hazards; and (c) prevent unauthorized access, use, disclosure, alteration, or destruction of Personal Data. b.well may update its security safeguards from time to time, provided that updates do not materially reduce the overall level of protection.

3.2  Security Incident Notification

b.well will notify Customer without undue delay, and in any event within forty-eight (48) hours of discovery, of any confirmed unauthorized access, disclosure, loss, alteration, or destruction of Personal Data Processed on Customer’s behalf (a “Security Incident”). Notification will include: (a) a description of the nature of the Security Incident; (b) the categories and approximate volume of Personal Data affected; (c) the likely consequences; and (d) the measures taken or proposed to address the incident. b.well will reasonably cooperate with Customer in investigating and remediating the Security Incident.

Notification of a Security Incident is not an acknowledgment of fault or liability by b.well.

4. Subprocessors

Customer grants b.well general authorization to engage Affiliates and third-party Subprocessors to assist in delivering the Services, subject to this Section. b.well’s current list of Subprocessors is published and maintained at icanbwell.com/legal/sub-processors/.

b.well will: (a) enter into a written agreement with each Subprocessor imposing data protection obligations at least as protective as those in this DPA; (b) remain responsible to Customer for the Subprocessor’s performance; and (c) provide Customer with at least ten (10) days’ prior written notice before engaging a new Subprocessor or materially changing the role of an existing one, by updating the published Subprocessor list and by sending an email notice to the Customer contact identified in the Order Form.

5. Data Subject Rights

b.well will promptly notify Customer if b.well receives a request from a Data Subject seeking to exercise rights under Applicable Data Protection Law (e.g., access, correction, deletion, portability, or objection). Unless otherwise set forth in the Order Form, b.well will not respond directly to such requests on Customer’s behalf unless required by Applicable Law or expressly instructed by Customer in writing.

b.well will provide Customer with reasonable technical and organizational assistance to enable Customer to fulfill Data Subject requests within applicable statutory timeframes, to the extent b.well can do so using the tools and information available to it. Customer is responsible for determining the applicable legal basis for each request and for communicating the outcome to the Data Subject.

For Consumer End User requests relating to data processed under ToS Section 6 (AI training, interaction data, de-identified data), b.well’s obligations are governed by ToS Section 6.3 and b.well’s published consumer-facing consent and rights mechanisms, not by this DPA.

6. Audit and Compliance Records

b.well will maintain records of its Processing activities as required by Applicable Data Protection Law. Upon thirty (30) days’ prior written notice, Customer may request an audit of b.well’s Processing activities once per calendar year to verify compliance with this DPA. Audits will be: (a) conducted at Customer’s sole expense; (b) limited to information reasonably necessary to verify DPA compliance; (c) subject to the confidentiality provisions of the Agreement; and (d) conducted in a manner that minimizes disruption to b.well’s operations.

Any independent auditor retained by Customer must execute a non-disclosure agreement with b.well on terms substantially similar to the Agreement’s confidentiality provisions before commencing any audit.

As of the Effective Date, b.well maintains an independent certification to the HITRUST cloud security framework (CSF) standard, issued by HITRUST based on testing performed by an independent CSF assessor. b.well will maintain its HITRUST Independent Certification throughout the Term and until the later of (a) expiration or earlier termination of the Agreement or (b) the date b.well no longer maintains or has access to Customer Data. On at least a bi-annual basis, b.well will undergo an independent assessment or audit in compliance with applicable HITRUST certification standards for all locations from which Services are provided or where Customer Data is stored or accessed, and will provide Customer with the results upon completion or within five (5) business days of Customer’s request. b.well further represents that offshore resources are within the scope of that certification, that all Customer Data will be Processed and stored in the United States, that access is limited to the minimum necessary, and that Customer may conduct an annual audit of b.well’s offshore activities.

7. Post-Termination Data Handling

Upon expiration or termination of the Agreement, b.well will, at Customer’s election, either return as requested during the wind-down period or securely delete and destroy all Personal Data Processed on Customer’s behalf within thirty (30) days, and provide written confirmation of such action upon request. b.well may retain: (a) backup or archival copies in accordance with its standard data retention schedule, which will be deleted as the schedule requires; and (b) Personal Data required to be retained by Applicable Law, which will be used only for the purpose that retention is required and subject to the confidentiality obligations of this DPA.

The data transfer obligations set forth in Order Form Section 4 (Term and Termination) apply to Customer Data generally and are not modified by this DPA.

8. Limitation of Liability

Notwithstanding anything to the contrary in the Terms of Service or this DPA, b.well shall reimburse Customer upon demand for direct, documented and reasonable costs associated with investigating, addressing, and responding to a reportable Security Incident; provided that such costs shall be limited to Notification Related Costs (defined below), up to the limit of Company’s actual recovery/reimbursement from its cybersecurity liability insurance policy. “Notification Related Costs” are limited to (i) preparation and mailing or other transmission of notifications or other communications to affected individuals, provided that Customer shall transmit notifications electronically to the maximum extent allowed by Applicable Data Protection Laws; and (ii) legal, consulting and accounting fees and expenses associated with Customer’s investigation of and response to such event, and excludes liability to the extent caused by the negligence, strict liability, breach of contract, or other fault of Customer, or its directors, officers, employees, or agents.

To the fullest extent permitted by applicable law, Customer and b.well expressly agree that any liability between them for concurrent, joint, or combined fault shall be several and proportionate to each party’s relative degree of fault, and not joint and several. The allocation of fault shall be determined by agreement of the parties or, failing agreement, by a court or other trier of fact of competent jurisdiction applying the governing law set forth in the Terms of Service. Nothing in this Section limits either Party’s rights to contribution or indemnity from any third party to the extent allowed by governing law. 

This Section 8 controls over any conflicting limitation of liability, exclusion of damages, or indemnification provision elsewhere in the Agreement with respect to a Security Incident or Personal Data.

9. Updates to This DPA

b.well may update this DPA from time to time to reflect changes in Applicable Data Protection Law, b.well’s products, or industry standards. Updates are effective upon posting at https://www.icanbwell.com/legal/health-network-startup-data-processing-addendum. Customer’s continued use of the Products and Services following the effective date of any update constitutes acceptance. b.well will provide Customer with at least thirty (30) days’ prior notice of any material change to this DPA. If Customer objects to a material change, Customer may terminate the Agreement upon thirty (30) days’ written notice.

10. Revision History

Effective Date Summary of Changes Link to prior version (as applicable)
June 5, 2026 First published https://www.icanbwell.com/legal/health-network-startup-data-processing-addendum-june-2026
August 13, 2026 Updated to clarify terms that align with b.well’s current standard requirements. https://www.icanbwell.com/legal/health-network-startup-data-processing-addendum-august-2026

Schedule A — Processing Details

The following table describes the Processing of Personal Data performed by b.well on Customer’s behalf under this DPA.

Controller: Customer
Role Controller of Personal Data provided to b.well under the Agreement
Obligations Ensure a lawful basis for Processing; provide required notices to Data Subjects; instruct b.well on Processing; and comply with Applicable Data Protection Law
Processor: b.well Connected Health, Inc.
Role Processor acting on Customer’s documented instructions
Processing purposes

Delivering the health.network Products and Services under the Agreement, either integrated through the b.well Embeddables or SDK Packages

Platform analytics and improvement (as authorized under ToS Section 6)

Startup Embeddables Package only: AI obligations (as applicable and described under ToS Section 6.3)

Subprocessor coordination and security operations

Compliance with Applicable Law

Categories of Data Subjects Consumer End Users of Customer’s application who interact with b.well Products and Services
Categories of Personal Data

Identity data (name, date of birth, contact information, government-issued ID for IAL2 verification)

Health records and clinical data retrieved through consumer-mediated access

Startup Embeddables Package only: as applicable, AI Health Assistant Interaction Data (queries, responses, metadata)

Usage and tracking data generated through interaction with the b.well Platform

Account credentials and authentication data

Special / Sensitive Data Health data including PHI where applicable. b.well applies safeguards consistent with the HIPAA Security Rule to all health data Processed under this DPA, whether or not b.well acts as a Business Associate with respect to that data.
Retention Personal Data is retained for the duration of the Agreement and deleted or returned within thirty (30) days of termination, subject to legal hold obligations and the archival exception in Section 7 of this DPA.
Transfer mechanisms Personal Data processed in the United States. Cross-border transfers, if any, subject to Standard Contractual Clauses or other lawful transfer mechanism as required.

DPA Definitions

The following terms, used in this DPA, supplement the definitions in Exhibit A of the Agreement:

“Applicable Data Protection Law” means all applicable data privacy, data protection, and information security laws and regulations governing the Processing of Personal Data by a Party, including without limitation: the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations; applicable U.S. state consumer privacy laws (including the California Consumer Privacy Act, as amended, and equivalent state statutes); and any other laws applicable to the Processing of health data or personal data in the jurisdictions in which Customer operates.

“Data Subject” means an individual to whom Personal Data relates, including Consumer End Users.

“Personal Data” means any information that identifies or could be used to directly or indirectly identify, describe, contact, locate, or otherwise relate to or be associated with an individual or household, as defined under Applicable Data Protection Law. For purposes of this DPA, Personal Data includes Protected Health Information (PHI).

“Processing / Process / Processed” means any operation or set of operations performed on Personal Data, including collection, recording, storage, use, access, disclosure, transmission, alteration, combination, restriction, deletion, or destruction, whether by manual or automated means.

“Security Incident” means any confirmed unauthorized access, disclosure, use, loss, alteration, or destruction of Personal Data Processed by b.well on Customer’s behalf.

“Subprocessor” means any Affiliate or third party engaged by b.well to Process Personal Data on Customer’s behalf in connection with the delivery of the Services.