BURNAID DATA PROCESSING ADDENDUM
AND
PRIVACY ARCHITECTURE SUMMARY
This Data Processing Addendum (“DPA”) forms part of the applicable Terms of Use, Subscription Agreement, License Agreement, Master Services Agreement, Order Form, or other agreement (collectively, the “Agreement”) entered into between BurnAid (“BurnAid”, “Processor”, “Service Provider”, “we”, “us”, or “our”) and the healthcare professional, healthcare organization, hospital, clinic, institution, university, research organization, or other customer (“Customer”, “Controller”, or “you”).
This DPA governs the processing of personal data and clinical assessment information by BurnAid in connection with the provision of its clinical reference, assessment, documentation, reporting, and calculation-support services.
This DPA should be read together with the BurnAid Terms and Conditions, Privacy Policy, Disclaimer, and any applicable subscription, licensing, institutional, or data processing agreement.
1. PURPOSE OF THIS DPA
BurnAid is a clinical reference, assessment, documentation, reporting, and calculation-support platform designed to assist qualified healthcare professionals with adult and pediatric burn-care scenarios, including:
- Burn assessment and evaluation
- Burn area mapping
- Total Body Surface Area (TBSA) estimation
- Burn severity assessment support
- Medication dose calculation support
- Fluid resuscitation calculation support
- Nutritional assessment and calculation support
- Clinical reference information and calculation support
- Clinical reporting
- Historical assessment review and analytics
- Related burn-care support functions
BurnAid is intended for use by qualified healthcare professionals and authorized healthcare staff. It is not intended for direct use by patients, children, parents, guardians, or the general public.
This DPA describes how BurnAid processes information while providing these services.
2. PRIVACY-BY-DESIGN ARCHITECTURE
BurnAid has been intentionally designed to minimize the collection, storage, and retention of patient-identifiable information wherever reasonably practicable.
A key architectural principle of BurnAid is that patient-identifying information is processed only when necessary to perform an active assessment and generate patient-specific reports.
BurnAid is designed not to retain direct patient identifiers in stored historical assessment records after completion of the assessment and report-generation process. These direct identifiers include patient names, hospital-assigned patient identifiers, medical record numbers, or similar direct patient-identifying information.
Historical records maintained by BurnAid are linked through internally generated BurnAid Assessment IDs and contain clinical assessment information de-linked from direct patient identifiers.
This architecture is intended to reduce privacy risks associated with long-term storage of patient-identifiable information. Customers acknowledge that certain retained assessment information may still constitute health-related information under applicable laws, even when direct patient identifiers have been removed.
3. PLATFORM CLASSIFICATION
BurnAid is not designed, marketed, or intended to function as:
- An Electronic Medical Record (EMR) system
- An Electronic Health Record (EHR) system
- A Hospital Information System (HIS)
- A Patient Registry
- A Long-Term Patient Record Repository
- A Patient Identity Management System
- A substitute for professional clinical judgment, specialist consultation, institutional protocols, local standards of care, or applicable legal and regulatory requirements
BurnAid is intended solely as a clinical reference, assessment, documentation, calculation-support, and reporting platform for qualified healthcare professionals.
The Customer remains responsible for maintaining official patient records within its own healthcare record systems where required.
4. ROLES OF THE PARTIES
For purposes of applicable data protection laws, the roles of the parties may vary depending on the Customer relationship, jurisdiction, and applicable legal requirements.
Customer
The Customer generally determines the purposes and means of processing and is responsible for:
- Determining the lawful basis and purpose for entering information into BurnAid
- Ensuring lawful collection and use of information
- Obtaining required patient, parent, guardian, institutional, or legal consents and authorizations where applicable
- Compliance with healthcare privacy laws and institutional policies
- Accuracy and completeness of information entered into BurnAid
- Reviewing, validating, storing, transmitting, and protecting exported reports and records
BurnAid
Where applicable, BurnAid acts as a processor, service provider, or business associate depending on the Customer relationship, jurisdiction, and applicable privacy laws.
BurnAid processes information for the purpose of providing, operating, securing, supporting, maintaining, and improving the Services described in the Agreement.
5. CATEGORIES OF DATA PROCESSED
5.1 User Account Information
BurnAid may process:
- User name
- Email address
- Mobile number, if provided
- Professional designation or specialty
- Hospital, clinic, institution, or organization name
- Country and region
- Account credentials and authentication information
- Subscription information
- Billing and payment-status information
- Usage information
5.2 Device, Technical, and Usage Information
BurnAid may process device, technical, diagnostic, and usage information as reasonably necessary for platform operation, security, reliability, analytics, customer support, and product improvement. This may include device type, operating system, browser type, application version, IP address, access timestamps, error logs, crash reports, features accessed, and usage frequency.
5.3 Temporary Assessment Information
During active patient assessment and report generation, BurnAid may process:
- Patient name
- Hospital patient identifier
- Medical record number
- Sex/Gender
- Height
- Weight
- Age
- Adult or pediatric assessment context
- Burn assessment information
- Burn location and mapping information
- Burn depth classifications
- Clinical observations
- Assessment-related information entered by the user
This information is processed for assessment, calculation, review, and report-generation purposes.
5.4 Retained Clinical Assessment Information
BurnAid may retain the following types of clinical assessment information in stored historical assessment records:
- BurnAid Assessment ID
- Sex/Gender
- Height
- Weight
- Age, where applicable
- Adult or pediatric assessment context
- Burn mapping information
- Burn location data
- Burn depth classifications
- TBSA calculations
- Medication dose calculation-support outputs
- Fluid resuscitation calculation-support outputs
- Nutritional assessment calculation-support outputs
- Clinical reference information and calculation-support outputs
- Clinical observations
- Assessment timestamps
- User information associated with the assessment
- Organization information associated with the assessment
Stored historical assessment records are designed not to retain patient names, hospital-assigned patient identifiers, medical record numbers, or similar direct patient identifiers.
6. PEDIATRIC PATIENT INFORMATION
BurnAid may be used by qualified healthcare professionals as a clinical reference, assessment, documentation, reporting, and calculation-support tool for both adult and pediatric burn-care scenarios.
Pediatric patient-related information may be entered by qualified healthcare professionals or authorized healthcare staff during active assessment and report-generation workflows. BurnAid is not directed toward children and is not intended for direct use by children, patients, parents, guardians, or the general public.
Customers remain responsible for obtaining any required patient, parent, guardian, institutional, or legal consents or authorizations and for ensuring compliance with applicable pediatric healthcare, privacy, consent, and institutional requirements.
7. TRANSIENT PROCESSING OF PATIENT IDENTIFIERS
Patient names and hospital-assigned patient identifiers are processed solely for:
- Clinical assessment workflows
- Report generation
- User review and validation of reports
- Assessment-related clinical activities
Upon completion of the assessment and report-generation process, BurnAid is designed not to retain direct patient identifiers in stored historical assessment records.
Customers acknowledge that reports generated and exported by users may contain patient-identifying information entered during the assessment process.
Responsibility for storage, transmission, sharing, printing, retention, and protection of exported reports rests solely with the Customer.
8. PURPOSES OF PROCESSING
BurnAid processes information for the following purposes:
- Providing clinical assessment functionality
- Performing burn mapping calculations
- Performing TBSA calculations
- Providing medication dose calculation support
- Generating fluid resuscitation calculation-support outputs
- Generating nutritional assessment calculation-support outputs
- Producing clinical reports
- Maintaining historical assessment records de-linked from direct patient identifiers
- Supporting analytics and reporting
- Managing subscriptions and billing
- Providing customer support
- Maintaining platform security
- Improving product performance and reliability
- Complying with legal obligations
- Resolving disputes and enforcing agreements where necessary
BurnAid does not sell customer data or patient-related information.
9. HISTORICAL RECORDS DE-LINKED FROM DIRECT PATIENT IDENTIFIERS
BurnAid retains historical assessment records using internally generated BurnAid Assessment IDs.
Because direct patient identifiers are not retained within stored historical assessment records, BurnAid is generally unable to independently identify or re-identify individual patients from stored assessment data.
Customers acknowledge that certain retained assessment information may still constitute health-related information, personal data, protected health information, or similar regulated information under applicable laws, even when direct patient identifiers have been removed.
10. SECURITY MEASURES
BurnAid implements reasonable technical, organizational, and administrative safeguards designed to protect information against unauthorized access, disclosure, alteration, misuse, or destruction.
Security measures may include:
- Encryption of data in transit
- Access controls
- User authentication
- Secure cloud infrastructure
- Security monitoring
- Audit logging
- Backup procedures
- Disaster recovery controls
While reasonable safeguards are implemented, no security system can guarantee absolute security.
11. SUBPROCESSORS
BurnAid may engage third-party subprocessors for:
- Cloud hosting
- Infrastructure management
- Payment processing
- Email delivery
- Analytics
- Monitoring
- Security services
- Customer support
BurnAid shall require subprocessors to maintain appropriate confidentiality and security obligations.
12. INTERNATIONAL DATA TRANSFERS
BurnAid supports users across multiple countries and jurisdictions.
Information may be processed, transferred, or stored outside the Customer’s country of residence.
Where required by applicable law, BurnAid shall implement reasonable safeguards to support lawful international transfers.
13. DATA RETENTION
BurnAid retains information only for as long as reasonably necessary to:
- Provide Services
- Maintain user accounts
- Support historical assessment records
- Generate reports
- Process subscriptions and payments
- Meet legal obligations
- Resolve disputes
- Enforce agreements
- Maintain system integrity
Direct patient identifiers processed during assessment are designed not to be retained within BurnAid’s stored historical assessment records after assessment completion and report generation.
14. CONFIDENTIALITY
BurnAid shall ensure that personnel with access to Customer information are subject to appropriate confidentiality obligations.
Access to information shall be limited to personnel with a legitimate operational need.
15. DATA SUBJECT RIGHTS
To the extent required by applicable law, BurnAid shall provide reasonable assistance to Customers in responding to requests relating to:
- Access
- Correction
- Deletion
- Restriction of processing
- Data portability
- Objections to processing
The Customer remains responsible for evaluating and responding to such requests where the Customer determines the purpose and means of processing.
16. SECURITY INCIDENTS
In the event BurnAid becomes aware of a confirmed security incident affecting Customer information, BurnAid shall:
- Investigate the incident
- Take reasonable steps to contain and mitigate the incident
- Notify affected Customers within a commercially reasonable timeframe where required by law
- Cooperate with Customers in providing relevant incident information
17. HEALTHCARE PRIVACY AND BUSINESS ASSOCIATE TERMS
Where BurnAid processes protected health information, electronic protected health information, or similar regulated health information on behalf of a healthcare organization, hospital, clinic, covered entity, business associate, or other regulated healthcare customer, additional contractual terms, data processing terms, or business associate terms may apply as required by applicable law.
Customers remain responsible for determining whether their use of BurnAid requires a business associate agreement, data processing agreement, institutional approval, patient authorization, parent or guardian authorization, or any other privacy, security, or healthcare compliance requirement.
18. AUDIT AND COMPLIANCE INFORMATION
Upon reasonable written request and subject to confidentiality obligations, BurnAid may provide Customers with information reasonably necessary to demonstrate compliance with this DPA.
Nothing in this section requires BurnAid to disclose confidential information, proprietary information, security-sensitive information, or information relating to other customers.
19. LIMITATION OF LIABILITY
Liability arising under this DPA shall be governed by the limitation of liability provisions contained within the applicable BurnAid Terms and Conditions, Subscription Agreement, License Agreement, or other governing agreement.
20. TERMINATION
This DPA shall remain in effect for as long as BurnAid processes information on behalf of the Customer.
Termination of the underlying Agreement shall automatically terminate this DPA, except for provisions that by their nature survive termination.
21. GOVERNING LAW
This DPA shall be governed by and construed in accordance with the laws of India, unless a separate written agreement between BurnAid and the Customer expressly provides otherwise.
Subject to applicable law and unless otherwise agreed in writing, any dispute, claim, or proceeding arising out of or relating to this DPA shall be subject to the exclusive jurisdiction of the competent courts located in Ernakulam, Kerala, India.
Nothing in this section shall prevent BurnAid from seeking urgent injunctive, equitable, or protective relief in any court of competent jurisdiction where necessary to protect its intellectual property, confidential information, security, systems, or legal rights.
22. CONTACT INFORMATION
Questions regarding this DPA may be directed to:
BurnAid Privacy Team
Email: privacy@burnaid.app
Website: https://burnaid.app
APPENDIX A – PROCESSING SUMMARY
Nature of Processing
Clinical assessment support, adult and pediatric burn-care reference support, burn mapping, TBSA estimation, medication dose calculation support, fluid resuscitation calculation support, nutritional assessment calculation support, clinical reference information, clinical reporting, historical assessment review, analytics, account administration, subscription management, and customer support.
Categories of Data Subjects
- Healthcare professionals
- Healthcare staff
- Adult patients undergoing burn assessment
- Pediatric patients undergoing burn assessment
Categories of Data
Temporarily processed during assessment:
- Patient name
- Hospital patient identifier
- Medical record number
- Clinical assessment inputs
- Assessment-related information entered by the user
Retained:
- Clinical assessment records de-linked from direct patient identifiers
- BurnAid Assessment ID
- Assessment calculations and outputs
- User account information
- Subscription and billing information
Key Privacy Design Feature
BurnAid is designed not to retain direct patient identifiers in stored historical assessment records following assessment completion and report generation. Historical records are maintained using BurnAid-generated assessment identifiers and clinical assessment information de-linked from direct patient identifiers, reducing patient-identification risk compared with traditional EMR/EHR platforms.
Purpose of Processing
Provision, operation, maintenance, security, support, reporting, analytics, subscription management, and continuous improvement of BurnAid services.