1. Roles and instructions
Where an institution determines the purposes of staff account administration and usage reporting, it acts as Controller and AfyaIndex acts as Processor. AfyaIndex will process that data only on documented instructions, these service terms, and applicable law.
2. Processing details
The subject matter is provision and administration of institutional access. Data may include staff identity, contact information, role, seat assignment, security logs, and workspace usage. Data subjects are authorised staff and administrators. Processing lasts for the subscription and applicable deletion or retention period.
3. Confidentiality and security
Authorised personnel are bound by confidentiality. Measures include role-based access, HTTPS, password hashing, administrative audit logs, backup controls, vulnerability maintenance, and incident-response procedures proportionate to risk.
4. Sub-processors and transfers
AfyaIndex may use vetted hosting, communications, authentication, analytics, support, and payment providers. AfyaIndex remains responsible for appropriate processor terms and safeguards for international transfers. A current sub-processor description is available on request.
5. Assistance and incidents
Taking account of the processing, AfyaIndex will reasonably assist with data-subject requests, security assessments, and regulator enquiries. AfyaIndex will notify the institution without undue delay after confirming a personal data breach affecting institution-controlled data and will provide available information needed for the institution’s obligations.
6. Return, deletion, and audit
At termination, institutional personal data will be returned or deleted on request unless law requires retention. Residual backup copies are isolated until their normal expiry. Reasonable compliance information is available on request; audits must protect other customers, security, and confidential information.
7. Order of precedence
This addendum supplements the institution agreement. If its data-protection terms conflict with general service terms, this addendum controls for the affected processing. Institution-specific security, residency, or clinical-data requirements must be agreed in writing before use.