Data Processing Addendum
Effective September 16, 2026
Contents
- 1. Definitions
- 2. Roles and Scope of Processing
- 3. Customer Obligations
- 4. Sub-Processing
- 5. Security
- 6. Security Breaches
- 7. Data Subject Requests and Assistance
- 8. Audits
- 9. Return and Deletion
- 10. International Transfers
- 11. Jurisdiction-Specific Terms
- 12. Liability
- 13. General
- Annex A: Description of Processing
- Annex B: EU, UK and Swiss Data Protection Laws
- Annex C: United States Privacy Laws
- Annex D: Security Measures
Sahha Pty Ltd (ACN 649 986 505)
This Data Processing Addendum (“DPA”) forms part of the agreement between Sahha Pty Ltd (ACN 649 986 505), a company incorporated in Sydney, Australia (“Sahha”, “we”, “us”), and the customer identified in that agreement (“Customer”) for the provision of the Sahha platform, SDK, API and related services (the “Agreement”). It sets out the terms on which Sahha processes Personal Data on Customer’s behalf.
By accepting the Agreement, Customer also accepts this DPA, including, where applicable, the EU Standard Contractual Clauses and the UK Addendum incorporated in Annex B. No separate signature is required. Capitalised terms not defined in this DPA have the meaning given in the Agreement.
1. Definitions
1.1 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where “control” means ownership of more than 50% of the voting interests of that entity.
1.2 “Aggregated Data” means information derived from Personal Data that has been anonymised (including by aggregation with data from other sources) so that it no longer constitutes Personal Data under Data Protection Laws, and so that it does not identify, and cannot reasonably be used to re-identify, Customer, any End User or any other individual, whether alone or in combination with other information.
1.3 “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
1.4 “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Supervisory Authority” have the meanings given in the applicable Data Protection Laws. Where a Data Protection Law uses equivalent terms (for example “business”, “service provider”, “personal information” or “agency”), those terms are read as the corresponding term in this DPA.
1.5 “Customer Data Use Policy” means Sahha’s policy governing permitted and prohibited uses of the Services and Sahha Outputs, available at https://sahha.ai/legal/data-use-policy/, as updated from time to time.
1.6 “Data Protection Laws” means all privacy and data protection laws that apply to the Processing of Personal Data under the Agreement, which may include the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the Privacy Act 2020 (NZ), EU Data Protection Laws, the CCPA and other United States state privacy laws, and the Health Insurance Portability and Accountability Act of 1996 (HIPAA) where the parties have entered into a separate business associate agreement.
1.7 “Data Subject Request” means a request from a Data Subject to exercise a right available under Data Protection Laws, such as access, correction, deletion, portability, restriction or objection.
1.8 “End User” means an individual who uses a Customer application into which the Sahha SDK or API is integrated, or whose data Customer otherwise submits to the Services.
1.9 “End-User Privacy Policy” means Sahha’s end-user privacy policy available at https://sahha.ai/legal/end-user-privacy-policy/, as updated from time to time.
1.10 “Device Data” means data collected from an End User’s smartphone or Wearable Device, whether passively through device sensors and operating system health frameworks (such as Apple HealthKit and Android Health Connect) or through a third-party data integration authorised by the End User.
1.11 “EU Data Protection Laws” means the EU General Data Protection Regulation 2016/679 (“GDPR”); the GDPR as incorporated into United Kingdom law and the Data Protection Act 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection (“FADP”); and any laws implementing or supplementing them.
1.12 “EU SCCs” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.
1.13 “Restricted Transfer” means a transfer of Personal Data that, absent an adequacy decision or other lawful basis, would be prohibited by Data Protection Laws.
1.14 “Sahha Outputs” means the scores, biomarkers, archetypes, insights, tags and other derived data generated by the Services from Device Data and other Personal Data.
1.15 “Security Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data Processed by Sahha under the Agreement. It does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as pings, port scans or failed log-in attempts.
1.16 “Security Measures” means the technical and organisational measures described in Annex D.
1.17 “Sensitive Data” means Personal Data that is given heightened protection under Data Protection Laws, including health information, biometric data, precise geolocation, government identifiers, financial account information, racial or ethnic origin, religious or political beliefs, sexual orientation and criminal records.
1.18 “Services” means the services Sahha provides to Customer under the Agreement.
1.19 “Sub-Processor” means any third party, including a Sahha Affiliate, engaged by Sahha to Process Personal Data on behalf of Customer. Sahha’s employees and individual contractors are not Sub-Processors.
1.20 “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as amended or replaced.
1.21 “Wearable Device” means a device worn on or attached to the body, such as a smartwatch, ring or fitness tracker, that collects health, activity, sleep or physiological data.
2. Roles and Scope of Processing
2.1 Roles. For Personal Data Processed under the Agreement, Customer is the Controller (or, where Customer acts on behalf of another controller, a Processor) and Sahha is Customer’s Processor or service provider. Annex A describes the subject matter, nature, purpose and duration of the Processing and the categories of Data Subjects and Personal Data.
2.2 Sahha’s instructions. Sahha will Process Personal Data only on Customer’s documented instructions, unless otherwise required by applicable law, in which case Sahha will inform Customer of that requirement before Processing unless the law prohibits it. The Agreement, this DPA and Customer’s configuration and use of the Services are Customer’s complete instructions. Additional instructions require written agreement between the parties.
2.3 Unlawful instructions. Sahha will promptly tell Customer if, in Sahha’s reasonable opinion, an instruction infringes Data Protection Laws. Sahha may suspend the relevant Processing until the instruction is withdrawn or confirmed as lawful.
2.4 Sensitive Data. Customer acknowledges that the Services are designed to Process health and wellbeing information. Customer must not submit Sensitive Data to the Services other than the categories described in Annex A. Sahha has no liability for Sensitive Data submitted in breach of this clause.
2.5 Aggregated Data. Customer authorises Sahha to anonymise Personal Data to create Aggregated Data, and to use Aggregated Data to operate, maintain, benchmark and improve the Services, including its models and scoring methodologies. Sahha will anonymise Personal Data to the standard required by Data Protection Laws and relevant Supervisory Authority guidance, and will Process Personal Data for this purpose only to the extent necessary to create Aggregated Data. Data that cannot be anonymised to that standard will not be used under this clause. Sahha will not attempt to re-identify Aggregated Data and will not disclose Aggregated Data in a form that identifies Customer.
3. Customer Obligations
3.1 Compliance. Customer will comply with Data Protection Laws in its use of the Services and in the instructions it gives Sahha, and is responsible for the accuracy, quality and lawfulness of the Personal Data and the means by which it was obtained.
3.2 Notice and consent. Customer is solely responsible for (a) giving End Users all notices required by Data Protection Laws, including a clear description of the Device Data collected through the Sahha SDK and how Sahha Outputs are used; (b) obtaining and recording all consents and permissions required for the collection of Device Data and the Processing of health information, including operating system permissions for sensor and health framework access; and (c) respecting any withdrawal of consent, including by stopping data collection and using the Services’ deletion functionality.
3.3 Permitted use. Customer will use the Services and Sahha Outputs only in accordance with the Agreement and the Customer Data Use Policy. Without limitation, Customer will not use Sahha Outputs to make decisions that produce legal or similarly significant effects on End Users where that use is prohibited by the Customer Data Use Policy or Data Protection Laws.
3.4 Not medical advice. Customer acknowledges that Sahha Outputs are not a medical device, diagnosis or clinical advice, and Customer is responsible for how Sahha Outputs are presented to End Users.
3.5 Indemnity. Customer will defend and indemnify Sahha and its Affiliates against any third-party claim, regulatory action, fine or loss arising from (a) Customer’s failure to provide required notices or obtain required consents; (b) Customer’s instructions to collect or Process Device Data; or (c) Customer’s use of Sahha Outputs in breach of clause 3.3. Sahha will promptly notify Customer in writing of any such claim, allow Customer to control its defence and settlement (provided Customer does not admit fault on Sahha’s behalf without Sahha’s consent), and provide reasonable assistance at Customer’s cost.
4. Sub-Processing
4.1 General authorisation. Customer gives Sahha general authorisation to engage Sub-Processors. Sahha’s current Sub-Processors are listed at https://sahha.ai/security/subprocessors/ (the “Sub-Processor List”). The Sub-Processor List identifies separately those service providers that do not Process End User Personal Data and are therefore outside the scope of this DPA.
4.2 Sub-Processor obligations. Sahha will enter into a written agreement with each Sub-Processor imposing data protection obligations no less protective than those in this DPA, to the extent relevant to the services provided by that Sub-Processor. Sahha remains responsible for the acts and omissions of its Sub-Processors as if they were its own.
4.3 New Sub-Processors. Sahha will update the Sub-Processor List at least 30 days before a new Sub-Processor begins Processing Personal Data. Customer may subscribe to notifications of updates by emailing security@sahha.ai. Where Sahha must engage a Sub-Processor urgently to maintain the security or availability of the Services, Sahha will give notice as soon as reasonably practicable.
4.4 Objections. Customer may object to a new Sub-Processor on reasonable data protection grounds by written notice to security@sahha.ai within the 30-day notice period. The parties will discuss the objection in good faith for up to 30 days. If they cannot resolve it, Sahha will either (a) not use that Sub-Processor for Customer’s Personal Data, or (b) allow Customer to terminate the affected Services on written notice without penalty, with a refund of any prepaid fees for the unused portion of the term. If Customer does not object within the notice period, the new Sub-Processor is deemed accepted.
4.5 Contact. Customer will direct all enquiries regarding Sub-Processors to Sahha and will not contact Sahha’s Sub-Processors about the Services without Sahha’s prior written consent.
5. Security
5.1 Security Measures. Sahha will implement and maintain the Security Measures, which are designed to protect Personal Data against Security Breaches and are appropriate to the nature of the Personal Data, taking into account the state of the art, costs of implementation, and the nature, scope, context, purposes and risks of the Processing.
5.2 Updates. Sahha may update the Security Measures from time to time, provided that updates do not materially reduce the overall level of protection of Personal Data.
5.3 Personnel. Sahha will ensure that personnel authorised to Process Personal Data are bound by appropriate confidentiality obligations, receive appropriate security and privacy training, and have access only to the extent necessary to perform the Services.
5.4 Customer responsibilities. Customer is responsible for its own secure use of the Services, including securing API keys, credentials and application tokens, configuring its applications securely, and protecting Personal Data while it is outside Sahha’s systems.
6. Security Breaches
6.1 Notification. Sahha will notify Customer without undue delay, and in any event no later than 24 hours after confirming a Security Breach affecting Customer’s Personal Data.
6.2 Content. Sahha’s notice will describe, to the extent then known, the nature of the Security Breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where information is not available at the time of the initial notice, Sahha will provide it in phases as it becomes available.
6.3 Response. Sahha will take reasonable steps to contain, investigate and remediate the Security Breach, and will provide reasonable assistance to Customer in meeting its own breach notification obligations under Data Protection Laws, including the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) and Part 6 of the Privacy Act 2020 (NZ).
6.4 Delivery. Sahha will send notices to the security or privacy contact nominated by Customer, or otherwise to Customer’s account owner by email. Customer is responsible for keeping its contact details current.
6.5 No admission. Sahha’s notification of or response to a Security Breach is not an acknowledgement of fault or liability.
7. Data Subject Requests and Assistance
7.1 Requests. If Sahha receives a Data Subject Request relating to Customer’s Personal Data, Sahha will not respond directly, other than to direct the Data Subject to Customer, unless required by law. Where legally permitted, Sahha will promptly forward the request to Customer.
7.2 Assistance. Taking into account the nature of the Processing, Sahha will make available functionality within the Services (including deletion via the API and dashboard) that enables Customer to respond to Data Subject Requests. Where Customer cannot fulfil a request using that functionality, Sahha will provide reasonable additional assistance. Sahha may charge for assistance that goes beyond what is reasonable, at its then-current professional services rates, on prior notice to Customer.
7.3 Impact assessments. Sahha will provide reasonable information to help Customer carry out data protection impact assessments or privacy impact assessments and any related consultation with a Supervisory Authority, to the extent Customer does not otherwise have access to that information.
8. Audits
8.1 Reports. Sahha undergoes an annual SOC 2 Type II audit by an independent third party covering the Security, Availability and Confidentiality trust services criteria. On written request, and subject to confidentiality obligations, Sahha will provide Customer with a copy of its most recent SOC 2 Type II report and reasonable responses to written security questionnaires, not more than once in any 12-month period.
8.2 On-site audits. If the information in clause 8.1 is not sufficient to demonstrate Sahha’s compliance with this DPA, or an audit is required by a Supervisory Authority or Data Protection Laws, Customer may conduct an audit, not more than once in any 12-month period, subject to the following: (a) Customer provides at least 30 days’ written notice and a proposed audit plan setting out scope, duration and start date; (b) the audit is conducted during normal business hours, without unreasonably interfering with Sahha’s operations; (c) any third-party auditor is reasonably acceptable to Sahha, is not a competitor of Sahha, and is bound by confidentiality obligations; (d) Sahha is not required to disclose information relating to other customers, its trade secrets, or information that would compromise its security; and (e) Customer bears its own costs and pays Sahha’s reasonable costs of supporting the audit.
8.3 Findings. Customer will promptly share audit findings with Sahha. Sahha will take reasonable steps to address any confirmed non-compliance with this DPA.
9. Return and Deletion
9.1 Return or deletion. Within 90 days after termination or expiry of the Agreement, Sahha will, at Customer’s choice, delete Customer’s Personal Data from its active systems or return it to Customer, unless Data Protection Laws require Sahha to retain it. Return is of Personal Data then held, using the Services. Customer may make its choice by written notice to security@sahha.ai at any time before, or within 30 days after, termination or expiry. If Customer does not make a choice within that period, Sahha will delete the Personal Data. Following any return, Sahha will delete remaining copies in accordance with this clause. Retained data remains subject to this DPA.
9.2 Backups. Personal Data in backups will be deleted in line with Sahha’s backup rotation cycle, currently no longer than 90 days after deletion from active systems, and will be protected in accordance with this DPA until then. Backups will not be restored to active systems except for disaster recovery, in which case Personal Data already deleted under this clause 9 will be re-deleted promptly. On Customer’s written request, Sahha will confirm in writing that deletion of Customer’s Personal Data from active systems under clause 9.1 has been completed, and the date by which remaining copies in backups will expire under this clause 9.2.
9.3 During the term. Sahha retains End User Personal Data for as long as the relevant End User profile is active. Customer may delete End User data at any time using the Services’ deletion API, without contacting support. Sahha will delete that data from active systems within 30 days of the deletion request (or within 3 days for data received through cloud integrations), and from backups in accordance with clause 9.2.
10. International Transfers
10.1 Location. Sahha is headquartered in Australia and hosts Personal Data on Amazon Web Services in the United States (us-east-1), across multiple availability zones. Hosting in other regions may be available to enterprise customers by written agreement. Sahha and its Sub-Processors may Process Personal Data in other countries, including New Zealand and the United States, as needed to provide the Services.
10.2 Safeguards. Sahha will ensure that any transfer of Personal Data outside the country in which it was collected complies with Data Protection Laws, including Australian Privacy Principle 8 and Information Privacy Principle 12 of the Privacy Act 2020 (NZ). Annex B sets out the transfer mechanisms that apply to Personal Data subject to EU Data Protection Laws.
11. Jurisdiction-Specific Terms
Annex B (EU, UK and Swiss Data Protection Laws) and Annex C (United States privacy laws) apply to the extent the relevant laws apply to the Processing, and form part of this DPA.
12. Liability
12.1 Each party’s liability arising out of or relating to this DPA, whether in contract, tort or otherwise, is subject to the limitations and exclusions of liability in the Agreement, to the extent permitted by Data Protection Laws. Any reference in the Agreement to a party’s liability means its aggregate liability under the Agreement and this DPA together.
12.2 Nothing in this DPA limits either party’s liability to Data Subjects under the EU SCCs or to the extent such limitation is prohibited by Data Protection Laws.
13. General
13.1 Term. This DPA remains in effect for as long as Sahha Processes Personal Data on Customer’s behalf under the Agreement. Clauses 3.5, 5, 9 and 12 survive termination.
13.2 Order of precedence. If there is a conflict, the following order applies: (a) the EU SCCs and UK Addendum, where applicable; (b) this DPA; (c) the Agreement; and (d) the Customer Data Use Policy.
13.3 Changes. Sahha may update this DPA to reflect changes in Data Protection Laws or the Services by giving Customer at least 30 days’ notice, provided that updates do not materially reduce the protection given to Personal Data. Any other amendment must be agreed in writing.
13.4 Severability. If any provision of this DPA is invalid or unenforceable, it will be read down to the minimum extent necessary, and the remainder of this DPA will continue in effect.
13.5 Governing law. Except where Data Protection Laws or the EU SCCs require otherwise, this DPA is governed by the laws of New South Wales, Australia, and each party submits to the non-exclusive jurisdiction of the courts of New South Wales.
13.6 Notices. Notices under this DPA are given in accordance with the Agreement. Privacy and security notices to Sahha must be sent to security@sahha.ai.
Annex A: Description of Processing
1. Subject matter and duration
Sahha’s provision of the Services to Customer in respect of End User Personal Data. Processing continues for the term of the Agreement and until deletion under clause 9.
2. Nature and purpose
Collection of Device Data from End User smartphones and Wearable Devices via the Sahha SDK and supported integrations; ingestion of data submitted through the API; storage, normalisation and analysis of that data; generation and delivery of Sahha Outputs to Customer; account administration, support, security monitoring and service improvement as described in the Agreement.
3. Categories of Data Subjects
End Users of Customer’s applications.
Sahha processes the business contact, authentication and billing details of Customer’s personnel who use the Sahha dashboard as an independent controller under its Privacy Policy (https://sahha.ai/legal/privacy-policy/). That processing is outside the scope of this DPA.
4. Categories of Personal Data
Identifiers: Customer-assigned End User IDs (external IDs), Sahha profile IDs, device identifiers, app and SDK version, IP address.
Profile data provided by Customer or End Users: age or date of birth, sex, gender, height, weight, country, and similar demographic attributes.
Device and behavioural data: step counts, movement and activity, screen time, device lock and unlock events, and similar passive smartphone sensor data.
Health and wellbeing data: sleep, heart rate, heart rate variability, resting heart rate, respiratory rate, blood oxygen, energy expenditure, exercise and workouts, body measurements, and similar Wearable Device and health framework data.
Profile and external identifiers contained in support communications (via Slack and Microsoft 365), where Customer raises support requests about specific End Users.
Sahha Outputs: scores (for example sleep, activity, readiness, wellbeing and mental wellbeing), biomarkers, archetypes, insights and tags.
5. Sensitive Data
Health and wellbeing data and Sahha Outputs derived from it, as listed above. Sahha does not collect geolocation data. Safeguards include encryption, strict access controls, data minimisation and the Security Measures in Annex D. Health data and Sahha Outputs are processed exclusively within Sahha’s AWS infrastructure using Sahha’s internal models, and are not sent to third-party AI services.
6. Frequency of transfer
Continuous for the term of the Agreement.
7. Retention
For the term of the Agreement, subject to Customer-initiated deletion during the term and clause 9 on termination.
Annex B: EU, UK and Swiss Data Protection Laws
1. Application
This Annex applies only where Sahha Processes Personal Data subject to EU Data Protection Laws. For that Personal Data, Customer is the Controller and Sahha is the Processor, and Sahha will comply with Article 28(3) GDPR (and its UK GDPR and FADP equivalents) as reflected in this DPA.
2. EU SCCs
Where Customer transfers Personal Data subject to the GDPR to Sahha in a country not recognised as providing adequate protection, the parties agree that the EU SCCs are incorporated into this DPA and completed as follows:
Module Two (controller to processor) applies. Where Customer is itself a processor, Module Three (processor to processor) applies.
Clause 7 (docking clause) does not apply.
Clause 9(a): Option 2 (general written authorisation) applies, with the notice period in clause 4.3 of this DPA.
Clause 11: the optional language does not apply.
Clause 13: the competent Supervisory Authority is the authority determined in accordance with Clause 13(a); where that cannot be determined, the Irish Data Protection Commission.
Clause 17: Option 1 applies; the governing law is the law of Ireland.
Clause 18(b): disputes are resolved by the courts of Ireland.
Annex I.A: the data exporter is Customer, as identified in the Agreement; the data importer is Sahha, contact David Pipe, Security Officer, security@sahha.ai. Each party is deemed to have signed Annex I by entering into this DPA.
Annex I.B: as set out in Annex A of this DPA.
Annex II: as set out in Annex D of this DPA.
Annex III: the Sub-Processor List.
3. UK Addendum
For transfers subject to the UK GDPR, the EU SCCs as completed above apply as varied by the UK Addendum. Tables 1 to 3 are completed with the information in section 2 of this Annex. For Table 4, neither party may end the UK Addendum under Section 19.
4. Switzerland
For transfers subject to the FADP, the EU SCCs apply with the following changes: references to the GDPR are read as references to the FADP; the competent Supervisory Authority is the Federal Data Protection and Information Commissioner; references to “Member State” include Switzerland so that Data Subjects in Switzerland may bring claims there.
5. Supplementary measures
Sahha encrypts Personal Data in transit using TLS 1.2 or higher and at rest using AES-256.
If Sahha receives a legally binding request from a public authority for Customer’s Personal Data, Sahha will, unless legally prohibited, notify Customer, attempt to redirect the authority to Customer, and challenge the request where Sahha reasonably considers it unlawful.
Sahha will disclose only the minimum Personal Data required to comply with such a request.
On request, not more than once a year, Sahha will tell Customer the number and type of such requests it has received in the preceding 12 months, to the extent legally permitted.
6. Alternative transfer mechanisms
If Sahha adopts an alternative lawful transfer mechanism (such as certification under the EU-US Data Privacy Framework or its UK and Swiss extensions), that mechanism will apply instead of the EU SCCs to the extent it covers the relevant transfers.
Annex C: United States Privacy Laws
-
Role. Where the CCPA or another US state privacy law applies, Sahha acts as Customer’s “service provider” or “processor”, and receives Personal Data for the business purpose of providing the Services.
-
No sale or sharing. Sahha will not sell or share (as those terms are defined in the CCPA) Personal Data received from Customer.
-
Use limitations. Sahha will not retain, use or disclose that Personal Data (a) for any purpose other than providing the Services and the business purposes permitted by the Agreement and applicable law, or (b) outside its direct business relationship with Customer. Sahha will not combine that Personal Data with personal information it receives from other sources, except as permitted by applicable law.
-
Compliance. Sahha will comply with its obligations under applicable US state privacy laws and provide the same level of protection they require. Sahha will notify Customer if it determines it can no longer meet those obligations.
-
Remediation. Customer may take reasonable and appropriate steps, including those set out in clause 8, to ensure Sahha uses Personal Data consistently with Customer’s obligations, and to stop and remediate unauthorised use.
-
Consumer health data. Where Washington’s My Health My Data Act or a similar consumer health data law applies, Customer is responsible for obtaining the consents required by that law, and Sahha will Process consumer health data only as a processor on Customer’s instructions.
-
HIPAA. Sahha does not act as a business associate under HIPAA unless the parties have signed a separate business associate agreement. Customer will not submit protected health information to the Services without such an agreement in place.
Annex D: Security Measures
1. Governance and assurance
Annual SOC 2 Type II audit by an independent auditor (Security, Availability and Confidentiality).
HIPAA-aligned controls, with a business associate agreement available on request.
Documented information security and privacy policies, reviewed and approved at least annually.
Defined security roles and responsibilities, and a risk management process covering administrative, technical and physical safeguards.
Vendor and Sub-Processor risk assessments, with written data protection terms.
2. People
Background checks for personnel prior to engagement, where permitted by law.
Security and privacy training at onboarding and annually.
Confidentiality obligations in employment and contractor agreements.
Documented offboarding with prompt revocation of access.
3. Access control
Role-based access on the principle of least privilege.
Single sign-on and multi-factor authentication for internal systems; multi-factor authentication required for production access.
Access reviews at least annually.
All access to customer data is logged with audit trails.
4. Data protection
Encryption in transit using TLS 1.2 or higher, and at rest using AES-256 via AWS-managed encryption, with keys managed in AWS Key Management Service under strict access policies.
Pseudonymous End User identifiers; Sahha does not require End User names or contact details to provide the Services.
Logical separation of customer data.
Health data and Sahha Outputs processed only within Sahha’s AWS environment using internal models; no third-party AI services receive health data.
Customer-controlled deletion via the API and dashboard.
Data retention and deletion in accordance with clause 9.
5. Infrastructure and operations
Hosting on Amazon Web Services, relying on AWS’s certified physical and environmental controls for data centres.
Deployment across multiple AWS availability zones, with VPC isolation, security groups and restricted administrative interfaces.
Automated daily backups of all customer and system data, with periodic restoration testing.
Documented change management with peer review and automated CI/CD pipelines.
Vulnerability scanning, dependency monitoring, and third-party penetration testing on an approximately annual basis.
6. Incident response and continuity
Documented incident response plan, tested periodically, with affected customers notified within 24 hours of a confirmed breach.
Security event logging and alerting.
Business continuity and disaster recovery planning.
7. Endpoint and office security
Managed company devices with disk encryption, automatic screen lock and endpoint protection.
Visitor and access controls for Sahha offices.