Skip to main content

Data Processing Agreement

This DPA forms part of the Terms of Service and outlines the terms governing the processing of personal data by Glandor Health.

Effective Date: April 2026 • Last Updated: April 2026

Roles and Responsibilities

  • Data Controller: The individual user utilizing Glandor Health services acts as the Data Controller, determining the purpose and means of processing personal data.
  • Data Processor: Glandor Health Technologies acts as the Data Processor, processing personal data solely on behalf of and according to the instructions of the Data Controller.
  • Processing Instructions: The processing of personal data is governed by the Terms of Service and Privacy Policy, which serve as documented instructions from the Controller.

Scope of Processing

  • Nature of Data: Bio-metrics, nutritional logs, and health insights as defined in the Privacy Policy.
  • Purpose: Providing AI-driven health analytics and personalized wellness coaching.
  • Duration: Data is processed for the duration of the user's active account status.

Sub-processors

  • Authorization: The Controller authorizes Glandor Health to engage sub-processors (e.g., cloud hosts, AI providers) to fulfill service obligations.
  • Compliance: We ensure all sub-processors are bound by data protection obligations equivalent to those in this DPA.
  • Notification: Material changes to our list of sub-processors will be communicated to users via email.

Technical & Organizational Measures

Glandor Health implements robust security measures to ensure a level of security appropriate to the risk, including:

Encryption of personal data in transit and at rest (AES-256).
Strict access controls and role-based access management (RBAC).
Regular vulnerability scanning and penetration testing.
Comprehensive incident response and disaster recovery plans.
privacy@glandor.com

Glandor Health Technologies • Data Protection Team