Data Processing Agreement

Document ID DPA-001 — Version 1.0 — Effective September 2026

This is the current version of Cord's Data Processing Agreement. It is incorporated by reference into your Order Form, platform agreement, or the Cord Health Terms of Service — accepting that agreement is acceptance of the version published here as of your acceptance date. You do not sign this page separately. Where patient health information is involved, this DPA does not stand alone — see 2. Relationship to the BAA below.

Recitals

This Data Processing Agreement ("DPA") is between Cord Labs LLC, a Delaware limited liability company ("Cord," "Processor," or "Service Provider"), and the health care provider, wellness practice, or other business entity that has accepted a Cord Order Form, platform agreement, or the Cord Health Terms of Service ("Provider," "Controller," or "Business").

This DPA is incorporated into and forms part of your agreement with Cord (the "Terms"). Provider uses the Cord Health platform for one or more of: patient and client management; clinical documentation; protocol, outcomes, and reporting tools; records digitization; electronic prescribing; and payment processing, FSA/HSA documentation, and patient billing (the "Services"). In providing the Services, Cord processes Personal Data on Provider's behalf, acting as a Data Processor under applicable privacy law.

1. Definitions

  • Applicable Privacy Law — the California Consumer Privacy Act as amended by the CPRA ("CCPA"), any other applicable US state privacy law, and their implementing regulations.
  • Controller — the party that determines the purposes and means of processing Personal Data. Provider is the Controller.
  • Data Subject — an identified or identifiable natural person the Personal Data relates to — primarily Provider's patients and clients.
  • Personal Data — any information relating to an identified or identifiable natural person, per the categories in Schedule 1.
  • Personal Data Breach — a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • Processor — the party that processes Personal Data on the Controller's behalf. Cord is the Processor.
  • Protected Health Information (PHI) — has the meaning at 45 C.F.R. § 160.103. PHI that is also Personal Data is processed subject to both this DPA and Cord's Business Associate Agreement ("BAA"); where they conflict on PHI, the BAA controls.
  • Sale — selling, renting, releasing, disclosing, or otherwise communicating Personal Data to a third party for monetary or other valuable consideration, per the CCPA.
  • Sensitive Personal Information — per the CCPA, including personal data revealing health or medical conditions (diagnosis, reason for visit, treatment).
  • Sub-processor — any processor Cord engages to process Personal Data for the Services. Cord maintains a current list, available on request.

2. Scope and Relationship to the BAA

This DPA governs Cord's processing of Personal Data for Provider, including Personal Data that also constitutes PHI (Schedule 1).

Mandatory pairing. This DPA does not stand alone where patient health information is involved. Where Provider uses the Services to process any patient health information, Cord's BAA is executed together with this DPA and remains in effect for as long as this DPA does. The parties execute the BAA without determining or conceding whether Provider is a Covered Entity or Business Associate under HIPAA — it applies to the extent HIPAA applies and otherwise serves as the parties' agreed standard. Where a BAA is in effect: the BAA governs all HIPAA-specific obligations; this DPA governs obligations under state privacy law for all Personal Data, PHI included, insofar as it's also Personal Data under that law; and where PHI is subject to both, the more protective standard applies — except breach-notification timelines, patient rights, and Business Associate obligations, which the BAA governs exclusively.

Cord processes Personal Data solely as Processor/Service Provider — it does not determine the purposes or means of processing beyond what the Services reasonably require. Provider is the Controller/Business.

Exception — Cord as Controller. Cord processes some data as a Controller in its own right: account registration data for Provider's administrative users (practice name, billing address, Stripe account information), de-identified aggregate platform-usage analytics, and data Cord must process to comply with law. That data isn't subject to this DPA — it's governed by Cord's Privacy Policy at cord.health/privacy.

3. Details of Processing

The subject matter is Cord's provision of the Services to Provider. Cord processes Personal Data for the duration of the Terms, plus any legally required retention period (Section 11), solely for the Business Purposes in Schedule 1 — never for another purpose without Provider's prior written authorization, except as required by law. Categories of Personal Data and Data Subjects are set out in Schedule 1.

4. Cord's Obligations as Processor

  • Process Personal Data only on Provider's documented instructions, including this DPA and your Terms; if an instruction appears to violate Applicable Privacy Law, notify Provider promptly and may suspend processing of the affected data pending resolution.
  • Keep personnel with Personal Data access under confidentiality obligations, by contract, professional duty, or statute.
  • Implement the security measures in Section 9.
  • Engage Sub-processors only per Section 7.
  • Assist with Data Subject rights requests per Section 8.
  • Handle deletion/return on termination per Section 11.
  • Make compliance information available and permit audits per Section 12.
  • Notify Provider of a Personal Data Breach per Section 10.

No sale, no behavioral advertising. Cord does not sell Personal Data, and does not retain, use, or disclose it for any commercial purpose beyond the Business Purpose, or use it for cross-context behavioral advertising.

De-identified data. Cord may create, use, and disclose data de-identified per applicable law (45 C.F.R. § 164.514 for PHI; reasonable safeguards otherwise), and will not attempt to re-identify it. This provision authorizes only the act of de-identifying — not any particular use of the resulting data. Where the parties have a separate data-use agreement (a Data Use Rights schedule, or a standalone data-use agreement), that agreement exclusively governs permitted uses of the de-identified data. Absent one, Cord's use of de-identified data derived from Provider's Personal Data is limited to operating, evaluating, and improving the Services.

5. Provider's Obligations as Controller

Provider represents it has a lawful basis for disclosing Personal Data to Cord and has given patients all required notices about Cord's processing on Provider's behalf. Provider is responsible for the accuracy of the Personal Data it provides — Cord is not liable for errors originating from Provider. Provider will not instruct Cord to process Personal Data in a way that violates Applicable Privacy Law, is responsible for receiving and routing Data Subject rights requests to Cord (Cord provides operational support, Provider is the primary responder), and — where Provider is a HIPAA Covered Entity — is responsible for its own Notice of Privacy Practices and for informing patients of Cord's role as Business Associate.

6. CCPA-Specific Provisions

Cord certifies it understands and will comply with the restrictions on a "Service Provider" under Cal. Civ. Code § 1798.140(ag)(1) — it will not sell or share Personal Data received from Provider; retain, use, or disclose it beyond the Business Purpose (including for Cord's own commercial purposes); retain, use, or disclose it outside the direct relationship with Provider; or combine it with Personal Data from other sources except as CCPA regulations permit.

Cord does not sell Personal Data, so no opt-out mechanism is required solely because of Cord's processing; if Provider collects and forwards opt-out signals, Cord honors them for any discretionary secondary use. Cord processes Sensitive Personal Information only as necessary for the Services and does not use it to infer characteristics beyond that.

Provider is the Business responsible for responding to CCPA rights requests from California consumers. On a documented request from Provider, Cord will, within 15 business days: provide an export of a Data Subject's Personal Data (right to know/access); delete it, subject to the retention exceptions in Section 11.4 (right to delete); correct inaccurate data (right to correct); or provide a portable copy in JSON or CSV (right to data portability). Cord already limits Sensitive Personal Information use to the Business Purpose, so the right to limit its use requires no separate action. Cord is not responsible for verifying a Data Subject's identity — that's Provider's responsibility before forwarding a request.

7. Sub-processors

Provider grants Cord general authorization to engage Sub-processors as necessary for the Services. Cord maintains a current list identifying each Sub-processor, its function, and whether it has PHI access, and provides that list to Provider on written request (including before this DPA is accepted, if requested) — the list is Cord's confidential information. Cord holds each Sub-processor to data-protection obligations no less protective than this DPA and, where applicable, the BAA, and gives Provider at least 30 days' advance notice — by email to Provider's designated privacy contact — before adding a new Sub-processor that will process Personal Data.

Provider may object to a new Sub-processor within 15 days of that notice; the parties negotiate in good faith, and if they can't agree and Provider's objection is commercially reasonable, Provider may terminate on 30 days' written notice. Cord remains fully liable for a Sub-processor's acts and omissions to the same extent as if Cord had processed the data directly.

8. Data Subject Rights

Cord provides reasonably necessary technical and operational assistance so Provider can fulfill Data Subject rights requests under Applicable Privacy Law. If a Data Subject submits a rights request directly to Cord, Cord acknowledges it within 5 business days, forwards it to Provider within 5 business days, and does not respond substantively without Provider's prior written authorization, unless required by law.

Cord provides this assistance at no additional charge for up to two Data Subject rights requests per calendar month per Provider; beyond that, Cord may charge a reasonable fee not exceeding its actual cost of compliance.

9. Security Measures

Cord implements and maintains, at minimum:

  • Encryption of Personal Data at rest (AES-256 via AWS server-side encryption) and in transit (TLS 1.2 or higher, with TLS 1.3 where available)
  • Access controls limiting Personal Data access to authorized personnel on a need-to-know basis
  • Audit logging of access to systems containing Personal Data
  • Annual security risk analysis and penetration testing
  • Annual workforce training on data privacy and security

Cord may update these measures over time as long as it doesn't materially reduce Personal Data's protection, and gives Provider at least 30 days' notice of any material reduction.

Zero PHI to non-BAA vendors. Cord does not transmit PHI or Sensitive Personal Information to any payment processor, fulfillment platform, or other vendor that hasn't executed a BAA or applicable DPA — an architectural rule enforced in Cord's code, not just policy.

10. Personal Data Breach Notification

Cord notifies Provider of a Personal Data Breach without unreasonable delay and no later than seventy-two (72) hours after becoming aware of it. Where the Breach involves PHI, notification is governed exclusively by the BAA, which applies the same 72-hour standard. To the extent available at the time, notification describes the Breach's nature (categories and approximate number of Data Subjects and records affected), Cord's privacy contact, the likely consequences, and measures taken or proposed — with further phases of information as they become available. Cord cooperates with Provider's own investigation and any required notification to Data Subjects or regulators. Notification is not an admission of fault or liability.

11. Data Retention and Deletion

Cord retains Personal Data for the Terms' duration and as the Services require. Unless Provider instructs otherwise, standard retention periods after the transaction or record-creation date are:

CategoryRetentionBasis
Transaction/payment records7 yearsIRS / tax
PHI (diagnosis, reason for visit, LMN content, intake)6–7 yearsHIPAA minimum / IRS FSA
Patient contact information5 years from last transactionOperations / on request
Breach notification records6 years45 C.F.R. § 164.414(b)
Audit logs6–7 yearsHIPAA / tax / audit

Provider may request deletion of a Data Subject's Personal Data at any time; Cord completes it within 15 business days, subject to retention exceptions for data required by law (HIPAA's 6-year minimum, IRS's 7-year rule, or other applicable law), ongoing legal proceedings or investigations, or active disputes involving the records — in which case Cord notifies Provider of the exception and retains only the minimum necessary data.

On termination or expiration, Cord will, within 30 days, return an export of all Personal Data it holds for Provider (JSON or CSV) and delete all remaining copies from its systems and Sub-processors' systems, subject to the retention exceptions above, and certify deletion in writing. Where Personal Data is embedded in backup systems that can't be selectively purged without disproportionate burden, Cord notifies Provider, extends this DPA's protections to that data, and deletes it at the earliest feasible opportunity.

12. Audits and Records

Cord maintains records of its processing activities sufficient to demonstrate compliance with this DPA, and makes compliance information available to Provider on written request within 30 days. Provider may audit Cord's compliance no more than once per calendar year, on 30 days' written notice, during normal business hours, without unreasonable disruption — at Provider's expense unless the audit finds a material breach, in which case Cord bears the reasonable audit cost. Cord may satisfy this obligation, in whole or part, with a relevant third-party certification (e.g., a SOC 2 Type II report or HIPAA compliance attestation) obtained within the prior 12 months, to the extent it covers the audit's subject matter.

13. International Data Transfers

As of this DPA's effective date, Cord processes Personal Data exclusively in the United States (AWS US regions) and does not transfer it outside the US. If that changes in connection with a future Sub-processor, Cord will notify Provider at least 30 days in advance, put an appropriate transfer mechanism in place first (e.g., Standard Contractual Clauses, an adequacy decision, or binding corporate rules), and update this DPA and the Sub-processor list accordingly. Cord is not currently subject to the EU GDPR, as it doesn't target EU residents or have an EU establishment; if that changes, this DPA will be amended to include EU Standard Contractual Clauses as applicable.

14. Term and Termination

This DPA is effective as of the date Provider accepts the Terms and remains in effect until the Terms expire or terminate, extended by any applicable retention period above. Sections 4, 9, 10, 11, and 15 survive termination for the duration of any applicable retention period.

15. General Provisions

This DPA is governed by Delaware law, except where Applicable Privacy Law (including the CCPA) requires otherwise; disputes are subject to the jurisdiction specified in your Terms. If this DPA conflicts with the Terms on Personal Data processing, this DPA controls; if it conflicts with the BAA on PHI, the BAA controls.

Amendments. Cord may update this DPA from time to time, giving at least 30 days' notice of a material change before it takes effect, via this page and by email to Provider's designated privacy contact. Continued use of the Services after a material change's effective date is acceptance; Provider may terminate within 30 days of that notice if it objects.

If any provision is held invalid or unenforceable, it's modified to the minimum extent necessary to make it enforceable, with the rest continuing in force. Together with your Terms and BAA (if applicable) and their schedules, this DPA is the entire agreement between the parties on Personal Data processing. Data Subjects are not third-party beneficiaries of this DPA except where Applicable Privacy Law requires it.

Schedule 1 — Data Processing Details

A. Categories of Personal Data

  • Patient contact information — name, email, phone
  • Payment data — last 4 card digits, transaction amount, date, status (full card numbers are processed by Stripe only)
  • FSA/HSA documentation data — service date, provider name, service description, eligibility flag
  • Health/medical data (PHI subset) — diagnosis codes, reason for visit, treatment rationale, intake responses — Sensitive
  • Provider administrative data — practice name, provider credentials, billing address
  • Platform usage data — session identifiers, feature-usage patterns (de-identified, aggregate)

B. Purposes of Processing

  • Payment processing — creating and managing transactions for health care services
  • Receipt generation — itemized receipts and payment confirmations
  • FSA/HSA documentation — Letters of Medical Necessity and explanation-of-benefits
  • Email delivery — receipts, Practitioner Recommendation Letters, payment notifications
  • Platform analytics — aggregate, de-identified usage analytics
  • Legal compliance — tax, HIPAA, and other required record-keeping

Never: sale of Personal Data, cross-context behavioral advertising, building individual consumer profiles for Cord's own commercial use, training AI/ML models on identifiable Personal Data, or any purpose outside the Business Purpose above.

C. Categories of Data Subjects

  • Patients and clients who pay through the Cord platform
  • Patients who submit intake forms or receive documentation through the platform
  • Provider's administrative users (account-management data only)

D. Sub-processors

Cord's current Sub-processors are available to Provider on written request, updated at least quarterly and whenever a new one is engaged.

E. Retention Summary

As in Section 11 above; de-identified aggregate analytics have no retention limit — they are not Personal Data.

Contact

Privacy Officer, Cord Labs LLC

301 Chestnut Street, San Carlos, California 94070 — Email: privacy@cord.health

Document History

VersionEffectiveChanges
1.0September 2026Initial published version.

This DPA is governed by the laws of the State of Delaware.