maven logo link
Confidential

Data Processing Agreement

  1. SECTION II - OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE
    1. Performance of Services. To the extent that the provision of Maven’s services under the Underlying Agreement renders Maven a Business Associate, as defined by HIPAA, Business Associate, its agents and employees (collectively referred to as “Business Associate”) agrees not to use or further disclose PHI other than as permitted or required by this BAA or as Required by Law.
    2. Safeguards for Protection of PHI. In accordance with 45 CFR Part 164, Subpart C, Business Associate shall develop, implement, maintain and use appropriate administrative, technical and physical safeguards to prevent the use or disclosure of PHI, in any form or media, received from, or created or received by Business Associate on behalf of, Covered Entity, other than as provided for by this BAA. Business Associate shall document and keep such security measures current.
    3. Reporting of Unauthorized Use and/or Security Breach. Business Associate will promptly report to Covered Entity any breach of security or use or disclosure of PHI, including breaches of unsecured PHI, as required by 45 CFR§164.410, upon becoming aware of such breach and in no case later than thirty (30) calendar days after discovery. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a security breach or use or disclosure of PHI by Business Associate in violation of the requirements of this BAA.
    4. Responding to and Reporting Security Incidents. Business Associate shall implement policies and procedures to address Security Incidents. Such policies and procedures shall include provisions for identifying and responding to suspected or known Security Incidents, mitigating, to the extent practicable, harmful effects of Security Incidents that are known to the Business Associate, and documenting Security Incidents and their outcomes. Business Associate shall promptly notify Covered Entity of any Security Incident of which it becomes aware, in accordance with 45 CFR §164.314; provided, however, the obligation to report a Security Incident shall not include the reporting of immaterial incidents such as unsuccessful attempts to penetrate Business Associate’s information systems.
    5. Use of Subcontractors. Business Associate agrees to ensure that any agent and/or subcontractor, to whom it provides PHI received from, or created or received by Business Associate, on behalf of Covered Entity, and who creates, maintains, or transmits PHI on behalf of Business Associate, adheres to the same restrictions and conditions that apply through this BAA to Business Associate with respect to such information.
    6. Access to PHI. Business Associate agrees to provide access to PHI in a Designated Record Set in order to meet the requirements under 45 CFR §164.524. In the event that Business Associate, in connection with the services, uses or maintains an Electronic Health Record of information of or about an Individual, then Business Associate shall upon request by Covered Entity or the Individual provide an electronic copy of the PHI to the Covered Entity or to the Individual or a third party designated by the Individual, all in accordance with 45 CFR §164.524(c)(2)(ii).
    7. Amendments by Business Associate. Business Associate agrees to make available for amendment and incorporate any amendment(s) to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 CFR §164.526.
    8. Access by DHHS. Business Associate agrees to make its internal practices, books and records including policies and procedures and PHI relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary for the purposes of the Secretary determining Covered Entity’s and Business Associate’s compliance with HIPAA and its implementing regulations.
    9. Accounting of Disclosures. Business Associate agrees to document disclosures of PHI and information related to such disclosures and to make an accounting of disclosures available to Covered Entity, or take other measures as reasonably necessary to satisfy Covered Entity’s obligations under 45 CFR §164.528.
    10. Carrying Out Obligations of Covered Entity. To the extent Business Associate is to carry out Covered Entity’s obligations under 45 CFR Part 164, Subpart E, Business Associate shall comply with the requirements of such Subpart that apply to the Covered Entity in the performance of such obligations.
    11. Security of Electronic PHI. Business Associate shall develop, implement, maintain and use appropriate administrative, technical and physical safeguards to preserve the confidentiality, integrity and availability of all electronic PHI received from, or created or received by Business Associate, on behalf of Covered Entity, which pertains to an Individual. Business Associate shall comply with the requirements set forth in 45 CFR §§164.306, 164.308, 164.310, 164.312, 164.314 and 164.316.
    12. Electronic Transactions and Code Set Standards. If Business Associate conducts any Standard Transaction for, or on behalf of, Covered Entity, Business Associate shall comply, and shall require any subcontractor or agent conducting such Standard Transaction to comply, with each applicable requirement of 45 CFR Part 162.
  2. SECTION III - PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
    1. General. Except as otherwise limited in this BAA or as provided in Section 3.2, Business Associate may use or disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the Underlying Agreement, provided that such use or disclosure would not violate HIPAA if done by the Covered Entity or the “minimum necessary” policies and procedures of the Covered Entity. Except as permitted by this BAA, Covered Entity shall not request or require Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by the Covered Entity.
    2. Specific. Except as otherwise limited in this BAA, Business Associate may use PHI if necessary for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. Except as otherwise limited in this BAA, Business Associate may disclose PHI if necessary to carry out the legal responsibilities of the Business Associate, provided that disclosure is required by law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached. Except as otherwise limited in this BAA, Business Associate may use PHI to provide Data Aggregation services to Covered Entity as permitted by 45 CFR §164.504(e)(2)(i)(B). Business Associate may use PHI to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR§164.502(j)(1).
    3. Except as otherwise limited in this BAA, Business Associate may de-identify PHI provided that the de- identification conforms to the requirements of the Privacy and Security Standards. The parties acknowledge and agree that de-identified data does not constitute PHI and is not subject to the terms of this BAA. Business Associate may use and disclose de-identified health information for any purpose permitted by law.
    4. Minimum Necessary. Business Associate shall request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use and/or disclosure.
  3. SECTION IV - OBLIGATIONS OF COVERED ENTITY
    1. Permissible Requests. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity (except as permitted by Article 3 of this BAA).
    2. Minimum Necessary. When Covered Entity discloses PHI to Business Associate, Covered Entity shall provide the minimum amount of PHI necessary for the accomplishment of Business Associate’s purposes under the Underlying Agreement.
    3. Permissions; Restrictions. Covered Entity warrants that it has obtained and will obtain any consents, authorizations and/or other legal permissions required under HIPAA and other applicable law for the disclosure of PHI to Business Associate. Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes may affect Business Associate’s use of disclosure of PHI. Covered Entity shall not agree to any restriction on the use of disclosure of PHI under 45 CFR 164.522 that restricts Business Associate’s use or disclosure of PHI under the Underlying Agreement unless such restriction is Required by Law or Business Associate grants its written consent.
    4. Notice of Privacy Practices. Except as Required by Law, with Business Associate’s consent, or this BAA, Covered Entity shall not include any limitation in the Covered Entity’s notice of privacy practices that limits Business Associate’s use or disclosure of PHI under any other agreement between the parties.
  4. SECTION V - TERM/TERMINATION
    1. Term. The term of this BAA shall be effective as of the Effective Date stated below and shall terminate upon the termination of the Underlying Agreement.
    2. Effect of Termination.
      1. Upon termination of this BAA for any reason, Business Associate, with respect to PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, shall:
        1. Retain only that PHI which is necessary to carry out its legal responsibilities;
        2. Return to Covered Entity (or, if agreed to in writing by Covered Entity, destroy) the remaining PHI that Business Associate still maintains in any form;
        3. Continue to use appropriate safeguards and comply with 45 CFR Part 164 Subpart C with respect to electronic PHI to prevent use or disclosure of the PHI, other than as provided for in this Subsection, for so long as Business Associate retains the PHI;
        4. Not use or disclose PHI retained by Business Associate other than for the purposes for which such PHI was retained and subject to the same conditions set forth in Section 3.2 that applied prior to termination; and
        5. Return to Covered Entity (or, if agreed to in writing by Covered Entity, destroy) the PHI retained by Business Associate when it is no longer needed by Business Associate to carry out its legal responsibilities.
      2. In the event that Business Associate determines that returning or destroying the PHI is infeasible, Business Associate shall provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the parties in writing that return or destruction of PHI is infeasible, Business Associate shall extend the protections of this BAA to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.
  5. SECTION VI - MISCELLANEOUS
    1. Priority of BAA. If any portion of this BAA is inconsistent with the terms of the Underlying Agreement, the terms of this BAA shall prevail. Except as set forth above, the remaining provisions of the Underlying Agreement shall remain unchanged.
    2. Documentation. Both parties shall retain all documentation required by HIPAA for six (6) years from the date of its creation or the date when the document was last in effect, whichever is later.
    3. Construction. This BAA shall be construed as broadly as necessary to implement and comply with ARRA and the HIPAA regulations. The parties agree that any ambiguity in this BAA shall be resolved in favor of a meaning that complies and is consistent with ARRA and HIPAA regulations.
    4. Modification of BAA. The parties recognize that this BAA may need to be modified from time to time to ensure consistency with amendments to and changes in applicable federal and state laws and regulations, including, but not limited to HIPAA. The parties agree to execute any additional amendments to this BAA reasonably necessary for each Party to comply with HIPAA. This BAA shall not be waived, amended or altered, in whole or in part, except in writing signed by the parties.

This Data Processing Agreement including its schedules (the "DPA") is incorporated into and forms part of the agreement between the entity or person identified as the customer in the applicable order form (“Customer”) and Maven Clinic, Co. ("Maven") under which Maven provides the Services (the "Agreement"). Unless otherwise defined herein, capitalized terms used in this DPA have the same meaning given to them under the Agreement. Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of its Affiliates permitted to use the Services under the Agreement.

WHEREAS, in connection with providing services to Customer under the Agreement, Maven will have access to and will process for or on behalf of Customer, Personal Data owned and provided to Maven by Customer;

WHEREAS, the Parties wish to enter into this DPA in connection with their respective obligations under Data Protection Laws;

NOW THEREFORE, in consideration of the mutual covenants and promises contained herein, and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, the Parties agree that the terms and conditions set forth below shall be added to the Agreement:

  1. 1. DEFINITIONS. For purposes of this DPA, the following terms shall have the meanings set out below. Capitalized terms used in this DPA but not defined herein shall have the meanings given to them in the Agreement.
“Applicable Data Protection Laws” means any data protection or privacy laws applicable to Maven’s Processing of Personal Data pursuant to the Agreement, including (as applicable, based on the location of Customer and/or the Data Subject):
  • (a) the (i) California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), (ii) Virginia Consumer Data Protection Act, (iii) Colorado Privacy Act, (iv) Connecticut Data Privacy Act, (v) Utah Consumer Privacy Act, (vi) Oregon Consumer Privacy Act, (vii) Texas Data Privacy and Security Act, (viii) Montana Consumer Data Privacy Act and (ix) once effective, similar comprehensive privacy laws in other U.S. states (together, “U.S. State Privacy Laws”);
  • (b) the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and any applicable national implementing laws;
  • (c) the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018 (“UK DPA”); and
“Controller” shall have the meaning as the equivalent term under Applicable Data Protection Laws including “Business” under the CCPA.
“Personal Data” means any information relating to an identified or identifiable natural person or as otherwise defined by or including the equivalent term Applicable Data Protection Laws.
“Personal Data Breach” shall have the meaning as the equivalent term defined under Applicable Data Protection Laws.
“Processing” shall have the meaning as defined under Applicable Data Protection Laws.
“Processor” shall have the meaning as defined under Applicable Data Protection Laws including “Service Provider” under the CCPA.
“SCCs” means the standard contractual clauses for Processors annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj; as may be amended, superseded or replaced.
“Subprocessor” shall have the meaning as the equivalent term defined under Applicable Data Protection Laws.
  1. 2. ROLES AND SCOPE OF PROCESSING.
    1. 2.1. Scope. This DPA applies to the extent that Maven Processes any Personal Data as described in Schedule 1 of this DPA.
    2. 2.2. Role of the Parties. The Parties agree that, for purposes of this DPA, Customer is a Controller with respect to the processing of the Personal Data, and Maven will process the Personal Data only as a Processor on behalf of and pursuant to the instructions of Customer. Each Party will comply with all laws, rules and regulations applicable to it in the performance of this DPA, including any Applicable Data Protection Laws.
    3. 2.3. Description of Processing. The subject matter of the data processing is the performance of the Services as described in the Agreement. Schedule 1 of this DPA sets out the nature, duration, and purpose of the processing , the types of Personal Data that Maven processes, and the categories of data subjects whose Personal Data is processed.
  2. 3. MAVEN OBLIGATIONS
    1. 3.1. Security Measures. Maven will implement and maintain appropriate technical and organizational measures designed to protect the Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure, as set forth in Schedule 2. Maven will ensure that any of its personnel who will engage in processing of Personal Data will be informed of the confidential nature of the Personal Data, receive training relevant to their responsibilities, and execute confidentiality agreements.
    2. 3.2. Personal Data Breach. As required by Applicable Data Protection Laws, Maven will provide notice to Customer upon confirming any Personal Data Breach, without undue delay. Such notice shall include the information required for Customer to meet its obligations under Applicable Data Protection Laws to the extent such information is reasonably available to Maven. If required information is not available, Maven will provide subsequent reports to supplement the initial notice. Maven’s response to, or notice of, a Personal Data Breach is not an acknowledgment by Maven of any fault or liability. Maven agrees to investigate any Personal Data Breach, and use commercially reasonable efforts to identify, prevent, mitigate, and remedy the effects.
    3. 3.3. Audits. Upon the Customer’s annual request, Maven shall provide its latest SOC 2 Type II report, proof of its HITRUST certification, or equivalent report (“Audit Materials”) in order to demonstrate compliance with this DPA. Customer shall treat the Audit Materials as Maven’s Confidential Information (as defined in the Underlying Agreement) and not further disclose the Audit Materials absent Maven’s prior written consent.
    4. 3.4. Data Subject Access Requests. Maven will promptly notify Customer if it receives a Data Subject Request impacting Personal Data under this DPA. Unless otherwise required by Data Protection Laws, Maven will not respond to a Data Subject Request, other than directing the data subject to Customer. Maven shall provide Customer with reasonable cooperation to assist Customer to fulfill any Data Subjects Requests relating to the processing of Personal Data under this DPA.
    5. 3.5. Subprocessors. Customer provides a general authorization to Maven to engage Subprocessors to provide services on its behalf, including those Subprocessors listed in https://www.mavenclinic.com/subprocessors Customer may subscribe to updates to the list of Subprocessors by emailing subprocessors@mavenclinic.com with the appropriate contact information. Maven must take steps to ensure that each Subprocessor provides sufficient guarantees that it will comply with Applicable Data Protection Laws and this DPA. Maven shall enter into a written agreement with the Subprocessor incorporating terms which are substantially similar to those set out in this DPA, and Maven will remain responsible for the performance of this DPA by any such Subprocessor.
  3. 4. CUSTOMER OBLIGATIONS.
    1. 4.1. Customer shall not instruct Maven to use or disclose Personal Data in any manner that would not be permissible under Data Protection Laws if done directly by Customer.
    2. 4.2. Customer will only provide to Maven the minimum amount of Personal Data necessary for the accomplishment of the processing purpose.
    3. 4.3. Customer represents and warrants that it has obtained and will obtain any consents, authorizations, and/or other legal permissions required under Data Protection Laws and other Applicable Law for the disclosure of Personal Data to Maven. Customer will notify Maven of any changes in, or revocation of, the permission by a data subject to use or disclose his or her Personal Data, to the extent that such changes may affect Maven’s use or disclosure of Personal Data.
    4. 4.4. Customer will not impose any restriction on the use or disclosure of Personal Data that will restrict Maven’s use or disclosure of Personal Data under the Agreement or this DPA unless such restriction is required by Applicable Law or Maven grants its written consent, which consent will not be unreasonably withheld.
  4. 5. US State Personal Information. To the extent the Personal Data contain personal information as defined by US State Privacy Laws, the Parties acknowledge and agree that Maven is a “service provider” or the equivalent term as defined under US State Privacy Laws. In that capacity, Maven shall: (i) use Customer’s Personal Data only as allowed in this DPA or Agreement; (ii) comply with the privacy protections required under the US State Privacy Laws; (iii) grant Customer rights to take reasonable and appropriate steps to ensure that Maven uses Customer’s Personal Data appropriately; (iv) notify Customer if it makes a determination that it can no longer meet its obligations herein; and (v) grant Customer the right, upon notice, to take reasonable steps to stop and remediate unauthorized use of Customer’s Personal Data by Maven.
    1. 5.1. Additionally, Maven will not (i) “sell” or “share” Customer’s Personal Data as those terms are defined under US State Privacy Laws, (ii) combine Customer’s Personal Data with any other personal information, unless expressly instructed by Customer for a specific purpose, and sole benefit of Customer, as permitted by the Agreement, or (iii) retain, use, or disclose Customer’s Personal Data for any purpose (including any commercial purpose) other than for the specific purpose of Maven’s performance under the Agreement. Maven certifies that it understands the preceding restrictions.
  5. 6. DATA TRANSFERS. Customer acknowledges and agrees that Maven may transfer and process Personal Data to and in the United States. Maven shall at all times ensure such transfers are made in compliance with the requirements of Applicable Data Protection Laws and this DPA, including the provisions below. To the extent that such transfer constitutes a Restricted Transfer the Parties shall rely upon the SCCs as the transfer mechanism. The parties agree that the SCCs shall be incorporated into this DPA implemented as below:
    1. 6.1. European Union. The Parties agree that Restricted Transfers governed by the EU GDPR are made pursuant to the SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows: (i) Module Two shall apply; (ii) the optional docking clause in Clause 7 shall apply; (iii) in Clause 9, Option 2 applies, and with the necessary information found in section 3.5; (iv) Clause 11’s optional language does not apply; (v) in Clause 17 (Option 1), the SCCs will be governed by Irish law; (vi) in Clause 18(b), disputes will be resolved before the courts of Ireland; (vii) Annex 1 shall be deemed completed with the information in Schedule 1; (viii) Schedule 1 contains the information required in Annex II of the SCCs; and (ix) Schedule 2 contains the information required in Annex III of the SCCs.
    2. 6.2. United Kingdom. For Restricted Transfers governed by the UK GDPR, the SCCs shall apply with the following modifications: (i) references to the “GDPR” shall mean the UK GDPR; (ii) Tables 1, 2 and 3 of the UK Addendum will be deemed completed with the information set out in the Schedules of this DPA; (iii) Table 4 in Part 1 of the UK Addendum shall be deemed completed by selecting both “exporter” and “importer”; (iv) references to the “competent supervisory authority” shall be interpreted as references to the Information Commissioner’s Office; and (v) any conflict between the SCCs and the UK Addendum shall be resolved in accordance with Section 10 and Section 11 of the UK Addendum.
    3. 6.3. Switzerland. For Restricted Transfers governed by Swiss Data Protection Laws, the SCCs shall apply with the following modifications: (i) references to the “GDPR” shall mean the Swiss FADP; (ii) references to “EU,” “Union,” and “Member State” shall be replaced with “Switzerland”; (iii) references to the “competent supervisory authority” and “competent courts” shall be interpreted as references to the “Swiss Federal Data Protection and Information Commissioner” and the “competent Swiss courts”; and (iv) the Standard Contractual Clauses shall be governed by the laws of Switzerland and disputes shall be resolved before the competent Swiss courts.
  6. 7. TERM AND TERMINATION
    1. 7.1. This DPA shall commence on the Effective Date of the Agreement and terminate upon the earliest of (i) the date of termination or expiration of the Agreement, or (ii) the destruction of Customer’s Personal Data.
    2. 7.2. Within 90 days following termination of this DPA, Maven shall destroy all of Customer’s Personal Data in Maven’s possession or control, save that this requirement shall not apply to the extent Maven is required by applicable law to retain some or all of Customer’s Personal Data, or to Customer’s Personal Data it has archived on back-up systems, which Maven shall securely isolate and protect from any further processing, except to the extent required by applicable law.
  7. 8. MISCELLANEOUS
    1. 8.1. Except as otherwise provided herein, notices under this DPA shall be sent to the contact information provided in the Agreement.
    2. 8.2. This DPA is incorporated into and subject to the terms and conditions of the Agreement. In the event of a conflict between the Agreement and this DPA, then this DPA shall control regarding the protection of Customer’s Personal Data. Any ambiguity of the language herein shall be construed to allow the Parties to comply with the Applicable Data Protection Laws.
    3. 8.3. This DPA may be amended only through mutual agreement of the Parties in writing. The Parties will work in good faith to amend this DPA if necessary to comply with an update to Applicable Data Protection Laws and will operate in compliance with such an update regardless of whether an amendment is in place.

SCHEDULE 1
DETAILS OF PROCESSING

Subject Matter of the Processing:

Performance of Services under the Agreement.

Categories of Data Subjects:
Customer’s employees and their dependents.

Categories of Personal Data:
Customer’s eligibility file, which may contain some or all of the following Personal Data, depending on which Maven services are covered:

  • Employee ID number
  • Employee business email address
  • First and last name
  • Date of birth
  • Home address
  • Gender
  • Employee office state location
  • Employee office country location
  • Employee start date
  • Employee eligibility date
  • Medical plan name
  • Insurer name
  • Coverage level
  • Dependent id(s)

Special Category Data: None

Nature and Purpose of Processing:
Maven shall Process Personal Data to determine whether individual data subjects are eligible for the Services, to perform initial outreach to eligibility individuals about the Services, to provide data reporting to the Customer, or as otherwise instructed by Customer.

Duration of Processing:
For the duration of the Services.

Frequency of Transfer:

Continuous as agreed by the Parties.

Competent Supervisory Authority:

EU GDPR: Ireland’s Data Protection Commission

UK GDPR: the Information Commissioner’s Office

Swiss FADP: Swiss Federal Data Protection and Information Commissioner

SCHEDULE 2
TECHNICAL AND ORGANISATIONAL MEASURES

Maven shall at all times implement and maintain the security measures identified below:

  • Minimum Requirements: the pseudonymisation and encryption of the Personal Data where appropriate and feasible; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • Backup: the ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident;
  • Testing: a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing;
  • Physical Access Control: the prevention of unauthorized persons gaining access to data processing systems;
  • Logical Access Control: the prevention of data processing systems being used without authorization;
  • Data Access Control: ensuring that persons entitled to use a data processing system gain access only to such Personal Data as they are entitled to access in accordance with their legitimate access rights, and that, in the course of processing or use and after storage, Personal Data cannot be read, copied, modified or deleted without authorization;
  • Data Transfer Control: ensuring that the Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media, and that the target entities for any transfer of the Personal Data by means of data transmission facilities can be established and verified;
  • Entry Control: ensuring the establishment of an audit trail to document whether and by whom the Personal Data have been entered into, modified in, or removed from data processing systems;
  • Control of Instructions: ensuring that the Personal Data is processed solely in accordance with Customer’s instructions;
  • Cyber security: ensuring measures to secure and defend Personal Data against unauthorized access , and to correct the Services to its original form in the event that it is modified without Customer’s consent;
  • Audit: Maven will cooperate with audits as described in Section 3.3 of the DPA.
  • Information Protection Policy: Maven must maintain an information protection/security policy and ensure on-going compliance controls are enabled according to SOC2 or NIST security standards.
  • Logging Information: Ensuring Security and Audit logs be retained for 360 days and access to security logs are restricted to authorized persons.
  • External Penetration Testing: Maven must validate its security controls using a third-party auditor at least once a year and after changes to the infrastructure that may impact Confidentiality, Integrity and Availability principles set forth by Art. 32 of GDPR.

Last updated: October 6, 2026

Rejoignez Maven

Employeurs
Régimes d'assurance maladie
Consultants
Ecosystem Partners
Particuliers
Devenez un fournisseur Maven

Programmes Maven

Fertilité et développement familial
Soins de maternité et du nouveau-né
Maven Milk
Parentalité et pédiatrie
Ménopause et santé à la quarantaine
Portefeuille Maven
Avantages gérés par Maven

Entreprise

À propos de nous
Carrières
Nous embauchons !
Appuyez sur
Solutions
Tarifs
Réserver une démo

Ressources

Parcours des membres Maven
NOUVEAU
Centre de ressources
Institut de recherche clinique
Webinaires
Blog
Études de cas
Partagez votre moment Maven

Retrouvez-nous sur

Inscrivez-vous à notre newsletter

© 2025 Maven Clinic Co. Tous droits réservés.
Conditions Confidentialité Sécurité Déclaration relative aux cookies Avis de pratiques de confidentialité Consumer Health Data Privacy NoticeSafety Information
Your Privacy Choices
© 2026 Maven Clinic Co. All rights reserved.
Verify Approval for www.mavenclinic.com