Terms of Service
These Terms of Service (these “Terms” or the “Agreement”) are entered into between you (“Customer” or “you”) and BklynHlth, Inc., a Delaware corporation doing business as Brooklyn Health (“Brooklyn Health”), and govern your access to and use of websites owned or operated by Brooklyn Health (the “Sites”), and Brooklyn Health offerings (the “Willis Platform”). The Sites, the Willis Platform, and documentation provided to You by Brooklyn Health (the “Documentation”) are collectively referred to as the “Services” under these Terms. If your use of the Willis Platform is governed by your organization’s Master Services Agreement with Brooklyn Health, please refer to that agreement.
By indicating your acceptance of these Terms or by using the Services, you agree to be bound by these Terms.
1.Brooklyn Health Obligations
1.1.Access to the Services. Subject to the terms and conditions of these Terms, Brooklyn Health hereby grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable right for you and, where applicable, your Authorized Users, to access and use the Services for your internal business purposes. “Authorized User” means employees, contractors, and other persons associated with you who access or use the Services through your account.
1.2.Data Protection. Brooklyn Health implements and maintains physical, technical, and administrative security measures designed to protect the applications and materials that you (or your Authorized Users) develop on or upload to the Services (“Your Content”) from unauthorized access, use, or disclosure. You and Brooklyn Health agree that they shall comply with and abide by their respective obligations under the Data Processing Addendum attached to this Agreement, which is incorporated into this Agreement by reference. Any categories of personal data or processing operations that are not set out in Brooklyn Health’s Data Processing Addendum will be processed and protected by Brooklyn Health in accordance with Brooklyn Health’s Privacy Policy found at https://brooklyn.health/privacy-policy.
2.Service Terms
2.1.Who may use the Services. You may only use the Services if you are of legal age to enter into these Terms according to the applicable laws and regulations in your jurisdiction.
2.2.Use Restrictions. Except as otherwise expressly authorized in these Terms, you will not, and will not encourage or assist third parties to: (i) reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, know-how, or algorithms relevant to the Services (except to the extent that such a restriction is impermissible under applicable law); (ii) provide, sell, resell, transfer, sublicense, lend, distribute, rent, or otherwise allow others to access or use the Services; (iii) copy, modify, create derivative works of, or remove proprietary notices from the Services; or (iv) use the Services in jurisdictions that are embargoed or designated as supporting terrorist activities by the United States Government or whose laws do not permit engaging in business with Brooklyn Health or use of the Services.
2.3.Account Management.
2.3.1.As part of the registration process, you will appoint one or more administrative users for your Willis Platform account. Each administrative user has the capacity, and you hereby confirm they have the authority, to manage your Willis Platform account, add or remove users, approve purchases, and take binding action relating to the Services and these Terms on your behalf.
2.3.2.Each Authorized User’s account is personal to the Authorized User to which it is issued. Account credentials may not be shared or used by anyone other than the individual to whom they were provisioned. You will ensure your Authorized Users comply with these Terms. You are responsible for all activities of your Authorized Users, and any failure on the part of your Authorized Users to comply with these Terms.
2.3.3.You will provide accurate and complete account information and maintain the accuracy and completeness of such information. You will maintain control over your Authorized Users’ accounts, including the confidentiality of usernames and passwords.
2.4.Your Content. You authorize Brooklyn Health and its service providers to use Your Content for the purposes of providing the Services and performing activities contemplated by these Terms (such as maintaining, securing, debugging, and otherwise performing quality control for the Services).
2.5.Feedback. You may voluntarily provide Brooklyn Health feedback, comments, or suggestions concerning the Services (collectively, “Feedback”). To the extent you provide Feedback, you hereby grant Brooklyn Health the right to use such Feedback to maintain, improve, and enhance Brooklyn Health’s products and services.
2.6.Usage Data. Brooklyn Health will have the right to collect and analyze data and other information relating to the access, use, and performance of the Services (“Usage Data”) and Brooklyn Health will be free (during and after the term) to use Usage Data in de-identified and aggregated form to maintain, improve, and enhance Brooklyn Health’s products and services. Examples of Usage Data include technical logs, metadata, telemetry data, and usage information about Your Content, such as how many times it is accessed. For clarity, Usage Data excludes Your Content itself.
2.7.Reservation of Rights. As between you and Brooklyn Health, Brooklyn Health owns all right, title, and interest in the Services. Except as expressly set forth in these Terms, each party retains all right, title, and interest in and to its intellectual property rights. All rights not expressly granted are reserved, and no license, covenant, immunity, transfer, authorization, or other right will be implied, by reason of statute, estoppel, or otherwise, under these Terms.
3.Confidentiality.
3.1.Confidential Information. Brooklyn Health (the “Discloser”) has disclosed or may disclose proprietary or non-public business, technical, financial, or other information (“Confidential Information”) to you (the “Recipient”). Our Confidential Information expressly includes non-public information regarding features, functionality, and performance of the Services, including security related information.
3.2.Obligations. The Recipient will use the Discloser’s Confidential Information only in connection with the use or provision of the Services. The Recipient will not disclose the Discloser’s Confidential Information to parties other than the Recipient’s employees, contractors, affiliates, agents, or professional advisors (“Representatives”) who need to know it and who have a legal obligation to keep it confidential. The Recipient will ensure that its Representatives are subject to no less restrictive confidentiality obligations than those herein. Notwithstanding the foregoing, the Recipient may disclose the Discloser’s Confidential Information: (a) if directed by Discloser; or (b) to the extent required by applicable legal process, provided that the Recipient uses commercially reasonable efforts to (i) promptly notify the Discloser in advance, to the extent permitted by law, and (ii) comply with the Discloser’s reasonable requests regarding its efforts to oppose the disclosure.
4.Warranties and Disclaimers.
4.1.Mutual Warranties. Each party represents and warrants to the other that: (a) the performance of these Terms by the executing party does not violate the terms or conditions of any other agreement to which it is a party or by which it is otherwise bound or require authorization or approval from any third party; and (b) it will perform its rights and obligations under these Terms in accordance with applicable law.
4.2.Brooklyn Health Warranties. Brooklyn Health represents and warrants to you that Brooklyn Health will provide access to the Willis Platform and any applicable support services in substantive conformity with the Documentation.
4.3.Disclaimer. EXCEPT FOR THE EXPRESS REPRESENTATIONS AND WARRANTIES STATED IN THIS SECTION, THE PARTIES MAKE NO REPRESENTATION OR WARRANTY OF ANY KIND WHETHER EXPRESS, IMPLIED (EITHER IN FACT OR BY OPERATION OF LAW), OR STATUTORY, AS TO ANY MATTER WHATSOEVER RELATING TO THIS AGREEMENT. BROOKLYN HEALTH EXPRESSLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, QUALITY, ACCURACY, TITLE, AND NON-INFRINGEMENT. THIRD-PARTY MATERIALS ARE PROVIDED BY THIRD PARTIES, NOT BROOKLYN HEALTH, AND ANY USE OF THIRD-PARTY MATERIALS IS SOLELY BETWEEN CUSTOMER AND THE APPLICABLE THIRD PARTY PROVIDER. BROOKLYN HEALTH DOES NOT WARRANT OR SUPPORT, AND WILL NOT HAVE ANY RESPONSIBILITY OR LIABILITY OF ANY KIND FOR, THIRD-PARTY MATERIALS.
5.Indemnity.
You will indemnify, hold harmless, and, at Brooklyn Health’s option, defend Brooklyn Health from any third party claims, disputes, demands, liabilities, damages, losses, and costs and expenses, including, without limitation, reasonable legal fees, arising out of or related to (a) Your Content; or (b) your violation of these Terms.
6.Limitations of Liability.
6.1.LIMITATION OF INDIRECT LIABILITY. UNDER NO CIRCUMSTANCES, AND UNDER NO LEGAL THEORY (WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, WARRANTY, OR ANY OTHER THEORY OF LIABILITY), WILL BROOKLYN HEALTH, ITS AFFILIATES AND ITS OR THEIR CONTRACTORS, EMPLOYEES, AGENTS, OR THIRD-PARTY PARTNERS, LICENSORS, OR SUPPLIERS (COLLECTIVELY, ITS “PARTY REPRESENTATIVES”), BE LIABLE FOR ANY SPECIAL, INDIRECT, INCIDENTAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES (INCLUDING LOSS OF PROFITS, DATA, OR USE OR COST OF COVER) ARISING OUT OF OR RELATING TO THESE TERMS OR THE USE OF OR THE INABILITY TO USE THE SERVICES, EVEN IF BROOKLYN HEALTH OR ITS PARTY REPRESENTATIVES HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
6.2.LIMITATION OF DAMAGES. UNDER NO CIRCUMSTANCES, AND UNDER NO LEGAL THEORY (WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, WARRANTY OR ANY OTHER THEORY OF LIABILITY), WILL THE TOTAL LIABILITY OF BROOKLYN HEALTH, ITS AFFILIATES, AND ITS OR THEIR PARTY REPRESENTATIVES FOR ANY AND ALL DAMAGES AND CAUSES OF ACTION ARISING OUT OF OR RELATING TO THESE TERMS OR THE USE OF OR THE INABILITY TO USE THE SERVICES, EXCEED THE GREATER OF (A) $100 OR (B) THE FEES PAID BY YOU TO BROOKLYN HEALTH IN THE 12 MONTHS PRECEDING THE EVENT GIVING RISE TO SUCH LIABILITY.
6.3.ALLOCATION OF RISK. EACH PROVISION OF THESE TERMS THAT PROVIDES FOR A LIMITATION OF LIABILITY, DISCLAIMER OF WARRANTIES, OR EXCLUSION OF DAMAGES IS TO ALLOCATE THE RISKS RELATING TO THESE TERMS BETWEEN THE PARTIES. THIS ALLOCATION IS REFLECTED IN THE PRICING OFFERED BY BROOKLYN HEALTH AND IS AN ESSENTIAL ELEMENT OF THE BASIS OF THE BARGAIN BETWEEN THE PARTIES. EACH OF THESE PROVISIONS IS SEVERABLE AND INDEPENDENT OF ALL OTHER PROVISIONS OF THESE TERMS. THE LIMITATIONS IN THIS SECTION WILL APPLY TO THE MAXIMUM EXTENT NOT PROHIBITED BY LAW AND NOTWITHSTANDING THE FAILURE OF ESSENTIAL PURPOSE OF ANY LIMITED REMEDY IN THIS AGREEMENT.
7.Term and Termination.
7.1.Term. These Terms will take effect the first time you access the Services and will continue in full force and effect until the termination, discontinuation, or cancellation of the order governing your use.
7.2.Termination.
7.2.1.Brooklyn Health may terminate your access to and use of the Willis Platform, at Brooklyn Health’s sole discretion, at any time and without notice or liability to you, but if Brooklyn Health terminates your access and the termination is not due to your breach of these Terms, Brooklyn Health will provide you with the option to return or destroy Your Content unless, in our reasonable discretion, Brooklyn Health is not legally permitted to do so (in which case any refund rights are null and void).
7.2.2.Upon any termination, discontinuation, or cancellation of Services or your Brooklyn Health account, the following provisions of these Terms will survive: Use Restrictions; Reservation of Rights; Data Protection; Confidentiality; provisions related to Usage Data, Your Content, and Feedback; Warranties and Disclaimers; Indemnity; Limitations of Liability; Termination; and the Miscellaneous provisions under Section 8.
8.Miscellaneous.
8.1.Changes to these Terms. Brooklyn Health may modify these Terms (and any policies or agreements referenced in these Terms) at any time. Brooklyn Health will post the most current version of these Terms. Brooklyn Health will endeavor to provide you with reasonable advance notice of any change to the Terms that, in our sole determination, materially affects your rights or your use of the Services. Brooklyn Health may provide you this notice through the Willis Platform, on Brooklyn Health’s website, and/or by email to the email address associated with your account. By continuing to use the Services after any revised Terms become effective, you agree to be bound by the new Terms.
8.2.Changes to the Services. Brooklyn Health may, in its sole discretion, add, change, or remove features or functionality of the Services; modify or introduce limitations to storage or other features; or discontinue the Services altogether at any time without notice.
8.3.Force Majeure. Brooklyn Health will not be liable for, or be considered to be in breach of or default under these Terms on account of, any delay or failure to perform as required by these Terms as a result of any cause or condition beyond its reasonable control, so long as it uses commercially reasonable efforts to avoid or remove those causes of non-performance. If Brooklyn Health believes, in good faith, that it is legally prohibited from providing you or your Authorized Users with the Services, Brooklyn Health may deactivate, delete, or otherwise restrict access to your account and/or cancel your subscription at Brooklyn Health’s sole discretion.
8.4.Notices. Any notices or other communications provided by Brooklyn Health under these Terms, including those regarding modifications to these Terms, will be given by Brooklyn Health through the Willis Platform, on Brooklyn Health’s website, and/or by email to the email address associated with your account.
8.5.Severability. The invalidity or unenforceability of any provision of these Terms will not affect the validity or enforceability of any other provision of these Terms and it is the intent and agreement of the parties that these Terms will be deemed amended by modifying such provision to the extent necessary to render it valid, legal, and enforceable while preserving its intent or, if such modification is not possible, by substituting another provision that is legal and enforceable and that achieves the same objective.
8.6.Assignment. These Terms (and your access to any of the Services) are not assignable or transferable by you without Brooklyn Health’s prior written consent. Any purported assignment in violation of this section is null and void.
8.7.Service Providers. For the avoidance of doubt, Brooklyn Health may engage third party service providers to support its performance of these Terms. Nevertheless, Brooklyn Health will remain responsible for compliance with these Terms.
8.8.Independent Contractors. No agency, partnership, joint venture, or employment is created as a result of these Terms, and neither party has any authority of any kind to bind the other party in any respect whatsoever.
8.9.Governing Law. These Terms and all claims arising out of or relating to the Terms will be governed by the laws of the State of New York without regard to its conflict of laws provisions. The United Nations Convention on Contracts for the International Sale of Goods is specifically disclaimed.
8.10.Dispute Resolution. You and Brooklyn Health both agree to resolve disputes arising out of or relating to these Terms, your use or contemplated use of the Services, or any aspect of your relationship or transactions with Brooklyn Health (each, a “Claim”) in binding arbitration instead of court, except that either party may bring suit in court to enjoin the infringement or other misuse of intellectual property rights. For purposes of this Section, a Claim includes disputes arising before the effective date of these Terms. The arbitrator will have the exclusive authority to resolve all threshold arbitrability issues, including whether these Terms are applicable, unconscionable, or enforceable, as well as any defense to arbitration. The arbitration will be held in New York, New York, before a single neutral arbitration applying the Rules of Commercial Arbitration of the American Arbitration Association. The arbitrator’s award shall be accompanied by a reasoned written opinion.
8.11.Interpretation. Whenever the words “including,” “include,” “includes” or "such as" are used in these Terms, they will be deemed to be followed by the phrase “without limitation.”
8.12.Entire Agreement. These Terms supersede all other agreements between the parties relating to its subject matter. In the event of any conflict among any mutually executed order and these Terms, the order of precedence will be: (a) any mutually executed order between the parties; (b) the Data Processing Addendum; (c) these Terms; and (d) the Privacy Policy. The parties agree that any terms and conditions stated in a customer purchase order or other customer ordering documentation (including any vendor management portal) are void.
Data Processing Addendum
Last Updated: August 6th, 2026
This Data Processing Addendum (“Addendum”) forms part of the agreement(s) between you (“Customer”) and Brooklyn Health covering Customer’s use of the Willis Platform to which this Addendum is incorporated (“Agreement”) and applies where, and to the extent that, Brooklyn Health processes Personal Data in Your Content that originates from the EEA or another Schedule 2 jurisdiction and/or that is otherwise subject to Data Protection Law. All capitalized terms not defined in this Addendum shall have the meanings set forth in the Agreement. This Addendum may be modified or amended only in writing signed by both parties. The parties hereto acknowledge having read this Addendum and agree to be bound by its terms.
1.Processing of Personal Data.
1.1.Description of Processing Activities. Details about processing activities, such as categories of data subjects and Personal Data processed are found in Schedule 1 (Description of Processing).
1.2.Brooklyn Health’s Role. As a Processor, Brooklyn Health will process Personal Data contained in Your Content (including Personal Data of Customer’s logged-in Authorized Users) only: (i) in accordance with documented Customer Instructions, or (ii) to comply with Brooklyn Health’s obligations under applicable laws and regulations.
1.3.Compliance with Law. Brooklyn Health and Customer will each comply with Data Protection Law. Customer is responsible for ensuring Customer Instructions comply with Data Protection Law. Brooklyn Health will notify Customer if it determines that an instruction infringes Data Protection Law.
1.4.Confidentiality. Brooklyn Health must ensure that persons authorized to process Your Content are subject to written or statutory obligations of confidentiality.
2.Security and Data Breaches.
2.1.Security Measures. Brooklyn Health has implemented and will maintain appropriate technical and organizational measures designed to protect the security, confidentiality, integrity, and availability of Your Content.
2.2.Data Breaches. Brooklyn Health must notify Customer without undue delay and, where feasible, within five (5) days after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Your Content processed by Brooklyn Health and/or its Sub-processors (“Data Breach”). Brooklyn Health will use commercially reasonable efforts to investigate and identify the root cause of the Data Breach, and, to the extent within Brooklyn Health's reasonable control, take reasonable and appropriate steps to mitigate and remediate the effects of the Data Breaches.
3.Sub-processors.
3.1.General Authorization. Customer generally authorizes Brooklyn Health to engage third-party service providers to process Your Content (each, a “Sub-processor”). Customer further agrees that Brooklyn Health may engage its affiliates as Sub-processors.
3.2.Written Agreement. Brooklyn Health will: (i) enter into written agreements with each Sub-processor that impose data protection obligations consistent with this Addendum; and (ii) remain liable to Customer where a Sub-processor fails to fulfill its data protection obligations.
3.3.Sub-processor List. Brooklyn Health maintains an up-to-date list of Sub-processors, available at https://www.brooklyn.health/sub-processors, which contains details about Sub-processor functions and the location of processing.
3.4.Notification of Changes. At least fifteen (15) days before a new Sub-processor begins processing Your Content, Brooklyn Health will add the Sub-processor to its sub-processor list and, if Customer has subscribed to notifications, provide Customer with written notice (“Sub-processor Notice Period”).
3.5.Objections to Sub-processors. Customers may object to Brooklyn Health’s appointment of a new Sub-processor during the Sub-processor Notice Period, provided such objection is in writing and based on reasonable grounds relating to data protection. In such an event, Brooklyn Health and Customer agree to discuss commercially reasonable alternative solutions in good faith. If Brooklyn Health and Customer cannot reach a resolution within the Sub-processor Notice Period, Brooklyn Health may proceed with the appointment of the Sub-processor and Customer, as its sole and exclusive remedy, may terminate the applicable services by providing written notice to Brooklyn Health.
4.Assistance and Cooperation.
4.1.Data Subject Rights. Taking into account the nature of the processing, Brooklyn Health will provide reasonable and timely assistance to Customer to enable Customer to respond to requests from individuals exercising their rights, provided that Customer cannot reasonably fulfill such requests independently by using the self-service functionality of the Willis Platform.
4.2.Impact Assessments and Consultations. Taking into account the nature of the processing, Brooklyn Health will provide reasonable assistance to Customer in connection with any data protection impact assessment or consultation with any regulatory authority that may be required under Data Protection Law.
4.3.Government and Other Third-Party Requests for Customer Personal Data. If Brooklyn Health receives a request from a third party, including a legally binding request from a governmental authority or law enforcement agency, for disclosure of Personal Data contained in Your Content, Brooklyn Health will (i) promptly notify Customer unless legally prohibited from doing so; (ii) where permitted, refer the requesting party to Customer; (iii) use reasonable efforts to challenge any request that is unlawful, disproportionate, or overbroad; and (iv) not disclose Personal Data contained in Your Content unless required to do so by law.
5.Deletion and Return of Customer Personal Data. At the end of providing the Willis Platform to Customer, Brooklyn Health will, as directed by Customer and at Customer’s option, delete or return all Your Content within thirty (30) days. Brooklyn Health may retain Your Content only to the extent required by Data Protection Law, subject to the confidentiality and processing restrictions in this Addendum.
6.Audit.
6.1.Audit Reports. Brooklyn Health conducts annual audits to verify the adequacy of its technical and organizational measures. Audits are performed at Brooklyn Health’s expense. Upon Customer's written request at reasonable intervals, and subject to appropriate confidentiality controls, Brooklyn Health will make available information, including summaries of its then-current third-party certifications and audit reports, so Customer can verify Brooklyn Health’s compliance with its data protection obligations in this Addendum.
6.2.Audit Right. Only to the extent Customer’s audit requirements under Data Protection Law cannot reasonably be satisfied through information provided in Section 6.1 (Audit Reports), Customer (or its appointed representative) may, at customer’s expense, conduct an audit to assess Brooklyn Health’s compliance with this Addendum. Any audit must be: (i) subject to reasonable confidentiality controls; (ii) conducted during Brooklyn Health’s regular business hours; (iii) with 45 days’ advance written notice; (iv) limited to once per year (unless required by a regulator or government authority); and (v) carried out in a manner that prevents unnecessary disruption to Brooklyn Health’s operations.
7.Region Specific Terms. Where Customer instructs Brooklyn Health to process Your Content originating in a region listed in Schedule 2 (Region Specific Terms), the applicable regional terms will apply, including those governing international transfers of Your Content.
8.Order of Precedence. If there is any conflict or inconsistency among the following documents, the order of precedence from highest to lowest will be: (1) the applicable terms stated in Schedule 2 (Region Specific Terms), including any transfer provisions; (2) the main body of this Addendum; and (3) the Agreement.
9.Definitions. The following capitalized terms will have the meanings set forth below:
9.1.“Controller” (also referred to as “Business” under applicable Data Protection Law) means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
9.2.“Your Content” means applications and materials that are developed by Customer or its Authorized Users on the Willis Platform or uploaded to the Willis Platform by Customer or its Authorized Users.
9.3.“Customer Instructions” mean: (i) processing to provide the Willis Platform and perform Brooklyn Health’s obligations in the Agreement (including this Addendum), (ii) investigating Data Breaches; and (iii) other reasonable documented instructions consistent with the terms of the Agreement. The parties agree that the Agreement and Customer’s use of the features and functionality within the Willis Platform are Customer’s complete and final instructions to Brooklyn Health in relation to processing of Personal Data contained in Your Content.
9.4.“Data Protection Law” means laws and regulations applicable to a party’s respective processing of Personal Data under this Addendum.
9.5.“Platform” means the Brooklyn Health offerings, products and services.
9.6.“Personal Data” means information about an identified or identifiable natural person, or which otherwise constitutes “personal information,” “personally identifiable information” or similar terms as defined in applicable Data Protection Law.
9.7.“Processor” (also referred to as “Service Provider” under applicable Data Protection Law) means the entity which processes Personal Data on behalf of the Controller.
10.Governing Law. This DPA will be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Law.
Schedule 1 - Description of Processing
1.Categories of Data Subjects:
1.1.“Authorized Users” - employees, contractors, and other persons associated with the Customer or its affiliates who access or use the Platform through the Customer’s account.
1.2.Other individuals whose Personal Data is included in Your Content.
2.Categories of Personal Data Processed:
2.1.Personal data contained in Your Content, which includes:
2.1.1.Personal Data pertaining to Customer’s logged-in Authorized Users (such as names and email addresses); and Personal Data residing within audio recordings and any other information identifying natural persons included in such audio recordings.
3.Sensitive Data or Special Categories of Data: Types of sensitive information processed may comprise medical or health-related data found in audio files. Applicable protective measures and security restrictions are detailed in Annex II.
4.The Frequency of the Transfer: Continuous.
5.Nature and Purpose of the Processing: Processing necessary to provide the Platform in accordance with the Agreement.
6.Duration of the Processing: Prior to the termination of the Agreement, Brooklyn Health will process Your Content until Customer elects to delete such Your Content via the self-service tools within the Willis Platform. Unless instructed to delete Your Content, Brooklyn Health will process Your Content for the term of the Agreement and will then delete such data in accordance with Section 5 (Deletion and Return of Customer Personal Data) of the Addendum.
7.Onward Transfers to Sub-processors: Brooklyn Health will transfer Your Content to Sub-processors as permitted in Section 3 (Sub-processors).
Schedule 2 - Region Specific Terms
Unless otherwise defined in the Addendum or the Agreement, all capitalized terms used in this Schedule 2 (Region Specific Terms) will have the meanings given to them in applicable Data Protection Law.
A.EUROPEAN ECONOMIC AREA
1.“Data Protection Law” includes the EU General Data Protection Regulation (GDPR) and the EU e-Privacy Directive.
2.The EU Standard Contractual Clauses (“EU SCCs”) will apply to Personal Data in Your Content that is transferred from the European Economic Area (EEA), including Iceland, Liechtenstein, and Norway, either directly or via onward transfer, to any country or recipient outside of the EEA that is not recognized by the relevant competent authority as providing an adequate level of protection for Personal Data. For such transfers, the EU SCCs are deemed entered into by Customer and Brooklyn Health, incorporated into the Addendum by reference, and completed as follows:
(a)Modules
(i)Module Two (Controller to Processor) applies where Customer acts as a Controller and Brooklyn Health acts as a Processor with respect to the Personal Data in Your Content.
(ii)Module Three (Processor to Processor) applies where Customer acts as a Processor and Brooklyn Health acts as a Sub-processor with respect to Personal Data in Your Content.
(b)Clause-Specific Provisions
For each applicable Module:
(i)In Clause 7 of the EU SCCs, the optional docking clause does not apply.
(ii)In Clause 9 of the EU SCCs, Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Section 3 (Sub-processors).
(iii)In Clause 11 of the EU SCCs, the optional language does not apply.
(iv)In Clause 17 of the EU SCCs, Option 1 applies, and the EU SCCs are governed by the law of Ireland.
(v)Clause 18(b) of the EU SCCs, disputes shall be resolved before the courts of Ireland.
(vi)In Annex I - Part A of the EU SCCs, the list of parties is set out in Annex I - List of Parties to this Schedule 2 (Region Specific Terms).
(vii)In Annex I - Part B of the EU SCCs, the description of the transfer is set forth in Schedule 1 (Description of Processing) of the Addendum.
(viii)In Annex I - Part C of the EU SCCs, the supervisory authority is the Irish Data Protection Commission.
(ix)In Annex II of the EU SCCs, the technical and organizational measures are set out in Annex II - Technical and Organizational Measures.
(x)In Annex III of the EU SCCs, a list of Brooklyn Health Sub-processors can be found at https://www.brooklyn.health/sub-processors.
B.UNITED KINGDOM
1.“Data Protection Law” includes the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
2.The UK International Data Transfer Addendum to the EU SCCs (“UK Addendum”) will apply to Personal Data that is transferred from the United Kingdom, either directly or via onward transfer, to any country or recipient outside of the United Kingdom that is not recognized by the relevant United Kingdom authority as providing an adequate level of protection for Personal Data. For such transfers, the UK Addendum is deemed entered into by Customer and Brooklyn Health, incorporated into this Addendum by reference, and completed as follows:
(a)In Table 1 of the UK Addendum, Customer’s and Brooklyn Health’s details and key contact information are set forth in Annex I - List of Parties.
(b)In Table 2 of the UK Addendum, the Approved EU SCCs, applicable Modules, and selected clauses are as described in Section 2 (European Economic Area) of this Schedule 2 (Region Specific Terms).
(c)In Table 3 of the UK Addendum:
(i)The list of parties is set forth in Annex I - List of Parties.
(ii)The description of the transfer is set forth in Schedule 1 (Description of Processing) of the Addendum.
(iii)The technical and organisational measures including technical and organisational measures to ensure the security of the data are set out in Annex II - Technical and Organizational Measures.
(iv)The list of sub-processors can be found at https://www.brooklyn.health/sub-processors.
(d)In Table 4 of the UK Addendum, either party may terminate the UK Addendum in accordance with its terms.
C.UNITED STATES
1.Where Personal Data in Your Content is subject to any applicable state privacy laws (“U.S. State Privacy Laws”) and Brooklyn Health acts as a Service Provider or Processor on behalf of Customer, Brooklyn Health will process such Personal Data in compliance with applicable U.S. State Privacy Laws and only on Customer Instructions for the limited and specified purposes set out in the Addendum. Brooklyn Health will not:
(a)retain, use, disclose, or otherwise process such Personal Data for any commercial purpose other than the limited and specified purposes contemplated by the Addendum, the Agreement, or as otherwise permitted under U.S. State Privacy Laws;
(b)“sell” or “share” such Personal Data within the meaning of applicable U.S. State Privacy Laws;
(c)retain, use, disclose, or otherwise process such Personal Data outside of the direct business relationship with Customer; or
(d)combine Personal Data with Personal Data obtained from other sources except as permitted by U.S. State Privacy Laws (e.g., to perform internal business operations, comply with law, or detect a Data Breach).
2.Brooklyn Health will notify Customer if it determines that it can no longer meet its obligations under U.S. State Privacy Laws. Customer may take reasonable and appropriate steps to stop and remediate any unauthorized processing of Personal Data.
Annex I - List of Parties
1 - Controller(s) / Data exporter(s):
Name: Customer
Address: Customer Address provided in the Agreement
Contact person’s name, position, and contact details: As set out in the Agreement
Activities relevant to the data transferred: Processing of Your Content for the purpose of the Agreement
Signature and date: See signature and date of the Addendum or, if the Addendum is incorporated in the Agreement by reference, see the signature (or electronic acceptance) and date of execution of the Agreement
Role (controller/processor): Controller, or Processor where Customer processes Your Content on behalf of a Controller (such as a Sponsor or CRO), in which case Brooklyn Health acts as Sub-processor and Module Three applies.
2 - Processor(s) / Data importer(s):
Name: BklynHlth, Inc., a Delaware corporation doing business as Brooklyn Health (“Brooklyn Health”)
Address: As set out in the Agreement.
Contact person’s name, position and contact details: As set out in the Agreement, with a copy to Data Protection Officer; dpo@brooklyn.health
Activities relevant to the data transferred under these Clauses: Processing of Customer Personal Data for the purpose of the Agreement
Signature and date: See signature and date of the Addendum or, if the Addendum is incorporated in the Agreement by reference, see the signature (or electronic acceptance) and date of execution of the Agreement.
Role (controller/processor): Processor
Annex II - Technical and Organizational Measures
1.Ethical and Professional Conduct. Brooklyn Health implements, maintains, and complies with mandatory written standards of ethical behavior, professional conduct, and regulatory compliance for all full-time, part-time, and contract personnel. Personnel are required to report any suspected ethical or regulatory violations through designated, non-retaliatory communication channels, and the company strictly prohibits bribery, kickbacks, and corrupt payments in any form across all business activities.
2.Quality Management System Governance. The organization operates a centralized electronic Quality Management System (eQMS) that enforces compliance with industry-standard Good Clinical Practice (GCP) guidelines, electronic record and electronic signature regulations, health information privacy acts, and global data protection laws. Operational oversight is maintained by a designated, independent Quality Officer and a Data Protection Officer who monitor daily compliance, evaluate data protection impact assessments, and conduct comprehensive periodic reviews of QMS effectiveness under senior management oversight.
3.Good Documentation Practices. All records, logs, and electronic files generated in the course of regulated activities are created, amended, and stored in strict compliance with data integrity principles ensuring that all information remains attributable, contemporaneous, legible, enduring, accurate, complete, consistent, original, available, and traceable. Automated or manual checklists, forms, and tools prohibit incomplete entries or blank fields, requiring non-applicable elements to be explicitly marked to ensure unambiguous record history.
4.Electronic Records and Signatures. All regulated electronic records are hosted within validated environments where logical access is strictly controlled. Electronic signatures executed within these systems serve as the legally binding equivalent of handwritten signatures, requiring unique identification and user re-authentication at the time of execution. Systems employ secure, computer-generated, and non-modifiable audit trails that automatically log the identity of the operator, precise timestamps, previous values, new values, and the reason for any changes.
5.Data Privacy and Protection. The organization integrates data privacy by design and by default across all systems and processing activities, restricting personal data collection and access to the minimum necessary to accomplish the intended purpose. A comprehensive Record of Processing Activities (RoPA) is maintained and reviewed at least annually to track processing categories, sub-processors, and international transfer mechanisms. Formal procedures are established to receive, log, verify the identity of, and respond to data subject rights requests, ensuring that requests concerning clinical trial datasets are escalated to the corresponding data controller and executed only under their written authorization. Data Protection Impact Assessments (DPIAs) are formally executed and approved prior to initiating any high-risk processing or system modifications.
6.Controlled Document Management. All governance documents, training modules, tools, and templates are managed through a formalized document control lifecycle within the eQMS, ensuring version control, mandatory peer and quality reviews, and authorized approval before release. Revisions are clearly documented in version history logs, and earlier versions are restricted from general access while being securely archived for regulatory inspections and business continuity.
7.Personnel Onboarding, Screenings, and Training. Prior to receiving logical access to company systems or client personal data, all personnel undergo comprehensive onboarding, credential verification against defined job descriptions, and mandatory background screenings. Background screenings follow a risk-based approach: personnel with standard operational access are screened via criminal search, global watchlist, SSN trace, and employment/education verification, while personnel accessing restricted client data undergo additional state and federal criminal searches. All personnel are screened against regulatory debarment and exclusion lists (including FDA debarment and OIG lists) upon hire and annually thereafter, and any failure of this check voids hiring immediately. Furthermore, all personnel must complete role-based information security and data privacy training within thirty days of hiring, which is refreshed at least annually or upon substantive policy revisions.
8.Deviation and Corrective Actions. The organization systematically captures, classifies, and manages departures from established procedures, audit findings, or customer complaints within a centralized electronic log. Major and critical deviations trigger formal investigations and root cause analyses to determine underlying failures, followed by the implementation of structured Corrective and Preventive Action (CAPA) plans. The Quality Officer conducts independent follow-up checks to verify that corrective measures are fully effective before any deviation is formally closed.
9.Data Retention and Disposal. Client personal data, clinical trial records, audit trails, and system configuration files are securely retained in accordance with contractually agreed retention periods or statutory requirements. Upon expiration of the mandated retention period, secure logical hard deletes are executed via database queries or APIs, or cryptographic erasure is performed by permanently deleting the associated encryption keys, rendering the data mathematically unrecoverable. For data residing within automated, immutable backup snapshots where surgical deletion is technically impossible, records are formally designated as beyond use to prohibit any processing, and technical controls are implemented to automatically re-execute logical deletions immediately following any system restoration.
10.Risk Management. The organization maintains a proactive risk management framework to identify, assess, quantify, and treat security, quality, and operational risks. Risks are scored using a standardized severity and likelihood matrix; medium risks require a documented mitigation or transfer response, while high risks require mandatory mitigation and cannot be accepted, with all residual risks undergoing periodic senior management review.
11.Vendor Qualification and Oversight. Sub-processors and third-party vendors who process sensitive or restricted data undergo rigorous pre-onboarding security and regulatory reviews to evaluate their information security posture, ISO 27001/SOC 2 certifications, and compliance with privacy laws. Legally binding Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs) are executed prior to vendor access, and qualified vendors are reassessed through formal security and compliance reviews at least annually.
12.Audits and Inspections. The organization maintains an independent internal audit program, scheduling and executing audits of critical systems and processes at least every two years under a risk-based schedule. Comprehensive procedures are established to host customer audits and regulatory inspections, and any findings are formally documented, investigated, and tracked to closure through the deviation and CAPA management framework.
13.Information Security Governance. The organization maintains a written information security program modeled after the ISO 27001 control framework, designed to protect the confidentiality, integrity, availability, and resiliency of all systems and client data.
14.Acceptable Use. Personnel are strictly prohibited from bypassing security controls, installing unapproved software, storing unencrypted restricted data on local devices, or using unauthorized cloud services to process client personal data. Business communications and data processing are restricted to company-managed systems and approved channels.
15.Access Control and User Authentication. Logical access to systems, databases, and networks is granted on a strict need-to-know basis in alignment with the principle of least privilege, managed through a centralized role-based access control matrix that is reviewed annually. Shared, generic, or group credentials are strictly prohibited, ensuring all actions are uniquely attributable to a single individual's verified identity. Access is only provisioned after mandatory security training is completed, and privileges are immediately adjusted or revoked within twenty-four hours of a role change, termination, or offboarding event. Regular quarterly access audits are conducted to detect and remediate any logical access drift.
16.Data Classification and Handling. All information assets are categorized into a standardized five-tier classification framework based on risk and sensitivity (Public, Company, Sensitive Company, Third-Party, and Restricted Data), with client personal data categorized as Restricted Data. Restricted data must reside exclusively within validated, regulatory-compliant cloud environments, and personnel are strictly prohibited from storing, downloading, or processing restricted data on local drives, personal devices, or portable storage media under any circumstances.
17.Physical Security. Physical access to the organization's corporate office spaces is strictly controlled. All visitors must check in and be logged in a centralized visitor tracker capturing arrival/departure times and their designated host. Visitors must be escorted at all times and are prohibited from unescorted access. Operating as a cloud-native organization with no on-premises servers or physical sensitive records, physical data center protection is ensured indirectly through rigorous security qualifications and audits of cloud hosting sub-processors.
18.Network Security. Perimeter security controls are established within the cloud-native environment using cloud-equivalent security groups, network access control lists, and web application firewalls to enforce logical boundaries. Personnel are required to connect only via encrypted network channels using strong passwords and WPA2 or stronger wireless security protocols, and host-based firewalls are programmatically enabled on all company-issued endpoint devices.
19.Cryptographic Control and Key Management. All client personal data is encrypted at rest using industry-standard, FIPS-compliant cryptographic algorithms (AES-256) and in transit across public or untrusted networks using TLS 1.2 or higher protocols. Cryptographic keys are securely generated, stored, and rotated automatically within the cloud provider's secure key management service, which isolates keys from encrypted storage and restricts access to authorized systems. A mandatory waiting period is enforced prior to key deletion to prevent accidental data destruction.
20.Asset Management. All company-issued endpoint devices used to access corporate systems or process non-public data are assigned unique identifiers, tracked in a centralized inventory, and programmatically enrolled in a Mobile Device Management (MDM) platform. The MDM platform automatically enforces password complexity, full-disk encryption, automatic operating system and security updates, and provides remote-wipe capabilities in the event of device loss or theft.
21.Business Continuity and Disaster Recovery. Automated, encrypted backups of production databases, system configurations, and snapshots are replicated to a geographically separate region daily. The cloud architecture supports a Recovery Time Objective (RTO) of twelve hours and a Recovery Point Objective (RPO) of twenty-four hours. Backups undergo formal quarterly verification checks and active restore tests into isolated test environments to confirm recoverability, and business continuity readiness is evaluated annually through structured tabletop exercises.
22.Incident Detection and Response. The organization maintains written policies and procedures to monitor, detect, and respond to security events and potential data breaches. Upon confirmation of a suspected security incident, executive management immediately assembles a cross-functional Incident Response Team to manage technical containment, preserve electronic evidence, and eradicate the root cause. If a data breach involving client personal data is confirmed, regulatory authorities (e.g., GDPR supervisory authorities within 72 hours) and the client are notified without undue delay and strictly in accordance with contractual and statutory timelines, followed by a mandatory post-incident review to prevent recurrence.
23.Change Management and System Validation. All system and software changes progress through strictly isolated development, staging, and production environments, and direct production code modifications are strictly prohibited. Code changes undergo mandatory peer reviews, security checks aligned with the OWASP Top 10 secure coding framework, and passing automated unit and integration tests. Changes affecting regulated features are classified and validated through formal computerized system validation procedures, requiring installation, operational, and performance qualification testing before deployment. Deployed software versions are formally pinned to prevent silent, unapproved updates.
24.Vulnerability and Patch Management. Automated vulnerability detection is maintained at both the application level and the infrastructure level. Security patches are prioritized and deployed based on CVSS scores: critical vulnerabilities are prioritized for immediate hotfix deployment, high-severity patches are applied within 7 days, medium-severity patches within 30 days, and low-severity patches during the next planned release cycle. Independent third-party penetration testing is conducted periodically against production environments, with all findings tracked and remediated.
25.AI/ML Model Credibility. Machine learning and artificial intelligence models undergo formal risk-based credibility assessments, classifying models into risk tiers based on decision consequence and model influence. Medium- and high-risk models require formal validation reports and Quality Officer approval prior to production integration. Development and training datasets are kept strictly independent of testing and validation datasets to prevent data leakage, and models are programmatically version-pinned and continuously monitored to detect data drift or performance degradation.