Data Processing Agreement — Summary
Last updated: April 28, 2026
Related documents: Privacy Policy · Subprocessors · Trust Center
This page summarizes how Wellness360 Technologies, Inc. ("Wellness360") processes personal data on behalf of our enterprise customers. The full Data Processing Agreement ("DPA") is part of your contract with us and is available on request at privacy@wellness360.co.
Our role
When you (the "Customer") use the Wellness360 platform to run a wellness program for your employees, you are the data controller (or, under some laws, the "personal information handler" or "business") and Wellness360 is the data processor (or "service provider" or "overseas recipient"). We process personal data only on your documented instructions and only for the purposes of providing the services you've purchased.
What we process
Only what the program needs. Data categories depend on the modules you enable, and typically include: name, corporate email, employee ID, and activity data (steps, challenge participation, points, rewards). Optional modules — Health Risk Assessments, biometric screenings, and claims integrations — process additional categories only when you affirmatively enable them.
What we commit to
- Your instructions only. We don't use your data for our own purposes, don't sell or share it, and don't combine it with data from other sources.
- Strong security. TLS 1.2+ in transit, AES-256 at rest, role-based access, MFA, annual third-party penetration testing. Wellness360 maintains HITRUST r2, SOC 2 Type II, ISO/IEC 27001, and US TX-RAMP Level 2. Current certifications and audit reports are published on our Trust Center.
- Sub-processors disclosed. Current list at wellness360.co/list-of-sub-processors. We give at least 30 days' notice of changes, and you have the right to object.
- Breach notification within 72 hours of our becoming aware.
- Support for your users' rights — access, correction, deletion, portability — under GDPR, UK GDPR, CCPA, PIPL, LGPD, and similar laws.
- Deletion on termination within 60 days (backups cycle out within 180 days).
- Lawful international transfers — EU Standard Contractual Clauses, UK Addendum, Swiss-compliant mechanisms, and a dedicated China PIPL schedule are available in the full DPA.
Where your data is hosted
Primary processing: Amazon Web Services, US-East-2 (Ohio, USA). Sub-processors are US-based unless otherwise listed. Wellness360 does not operate a legal entity, employees, or infrastructure in mainland China.
The full DPA
The complete DPA — including EU SCCs, UK Addendum, China PIPL Addendum, CCPA/US state terms, and a HIPAA Business Associate Agreement on request — is provided as part of your enterprise contract. Enterprise customers can also request a pre-signing copy from privacy@wellness360.co.