Data Processing Agreement
This DPA forms part of the Terms of Service and outlines the terms governing the processing of personal data by Glandor Health.
Effective Date: April 2026 • Last Updated: April 2026
Roles and Responsibilities
- Data Controller: The individual user utilizing Glandor Health services acts as the Data Controller, determining the purpose and means of processing personal data.
- Data Processor: Glandor Health Technologies acts as the Data Processor, processing personal data solely on behalf of and according to the instructions of the Data Controller.
- Processing Instructions: The processing of personal data is governed by the Terms of Service and Privacy Policy, which serve as documented instructions from the Controller.
Scope of Processing
- Nature of Data: Bio-metrics, nutritional logs, and health insights as defined in the Privacy Policy.
- Purpose: Providing AI-driven health analytics and personalized wellness coaching.
- Duration: Data is processed for the duration of the user's active account status.
Sub-processors
- Authorization: The Controller authorizes Glandor Health to engage sub-processors (e.g., cloud hosts, AI providers) to fulfill service obligations.
- Compliance: We ensure all sub-processors are bound by data protection obligations equivalent to those in this DPA.
- Notification: Material changes to our list of sub-processors will be communicated to users via email.
Technical & Organizational Measures
Glandor Health implements robust security measures to ensure a level of security appropriate to the risk, including:
Encryption of personal data in transit and at rest (AES-256).
Strict access controls and role-based access management (RBAC).
Regular vulnerability scanning and penetration testing.
Comprehensive incident response and disaster recovery plans.
privacy@glandor.com
Glandor Health Technologies • Data Protection Team