This Data Processing Addendum ("DPA") is incorporated into the Salus Platform Agreement between Salus Solutions, Inc. ("Salus") and the institution identified on an Order Form ("Customer"). It governs Salus's processing of Personal Data contained in Customer Data. Capitalized terms used but not defined here have the meanings given in the Platform Agreement. Where this DPA conflicts with the Platform Agreement on the subject of data protection, this DPA controls.
Sections
1. Definitions
"Personal Data" means information within Customer Data that identifies or is reasonably capable of being associated with an individual, including education records under FERPA.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
"Security Incident" means a confirmed unauthorized acquisition, access, use, or disclosure of Personal Data in Salus's possession.
"Subprocessor" means a third party engaged by Salus that Processes Personal Data on Salus's behalf.
"Privacy Laws" means the privacy and data protection laws applicable to Customer's use of the Services, including FERPA, applicable state student privacy laws, and applicable state consumer privacy statutes.
2. Roles of the Parties
Customer determines the purposes and means of Processing Personal Data through the Services. Salus Processes Personal Data only on Customer's documented instructions.
Under FERPA, Customer designates Salus as a school official with a legitimate educational interest in the education records Salus Processes. Salus performs an institutional service for which Customer would otherwise use its own employees, remains under Customer's direct control with respect to the use and maintenance of those records, and will not redisclose them except as Customer directs or as required by law.
Under applicable state consumer privacy statutes, Salus acts as a service provider or processor. Salus will not sell Personal Data, will not share it for cross context behavioral advertising, will not retain, use, or disclose it for any purpose other than performing the Services or as otherwise permitted by law, and will not combine it with personal information Salus receives from another source except as permitted for a service provider.
Customer is responsible for providing any notice and obtaining any consent required for Salus to Process Personal Data, and for the accuracy and legality of the Personal Data it provides.
3. Scope and Purpose of Processing
Salus Processes Personal Data to provide, maintain, secure, troubleshoot, and support the Services, and for no other purpose. This includes ingesting records from Source Systems, producing analyses and Outputs for Customer's review, maintaining the audit trail, publishing records Customer approves for publication, sending communications Customer configures, and responding to Customer's support requests.
Salus does not use Personal Data to train or fine tune foundation models, and does not use Personal Data to create or improve a model made available to any other customer. Salus's Subprocessors are contractually prohibited from doing so.
Configuration derived from Customer's own review decisions, such as institution specific classification guidance, is stored as data within Customer's environment and applied only to Customer.
Salus may generate aggregated and de-identified data about use of the Services and may use it to operate, secure, and improve the Services. Aggregated and de-identified data contains no Personal Data and may not be used in a way that identifies Customer, an Authorized User, or any individual, and Salus will not attempt to re-identify it.
Annex A describes the subject matter, duration, nature, categories of data subjects, and types of Personal Data Processed.
4. Confidentiality and Personnel
Salus limits access to Personal Data to personnel who require it to perform the Services, including support and troubleshooting, and who are bound by written confidentiality obligations.
Salus maintains role based access controls for its own personnel, reviews access periodically, revokes it promptly on role change or departure, and logs access to Customer environments.
Salus personnel receive security and privacy training at onboarding and on a recurring basis.
5. Security
Salus maintains the technical and organizational measures described in Annex B, which are designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access. Salus will not materially reduce those measures during a subscription term.
Salus assesses its security program on an ongoing basis and engages independent third parties to test the Services.
6. Subprocessors
Customer authorizes Salus to engage the Subprocessors listed in Annex C, and to engage additional Subprocessors in accordance with this Section.
Salus performs diligence on each Subprocessor before engagement and imposes data protection obligations no less protective than those in this DPA. Salus remains responsible for its Subprocessors' performance.
Salus will give Customer at least thirty days notice before adding or replacing a Subprocessor that Processes Personal Data. Customer may object on reasonable data protection grounds within that period, and the parties will work in good faith to resolve the objection. If they cannot, Customer may terminate the affected Order Form with a pro rata refund of prepaid, unused fees.
7. Data Subject Requests
Customer administers requests from individuals to access, correct, delete, or restrict Personal Data. The Services provide functionality for Customer to locate, export, correct, and delete records.
If Salus receives a request directly from an individual, it will not respond substantively and will refer the individual to Customer, notifying Customer promptly unless prohibited by law.
Salus will provide reasonable assistance, at Customer's expense where the assistance is substantial, in responding to requests and in conducting a privacy impact assessment relating to the Services.
8. Security Incidents
Salus will notify Customer without undue delay, and in any event within seventy-two hours, after confirming a Security Incident affecting Customer's Personal Data.
The notice will describe the nature of the incident, the categories and approximate volume of Personal Data involved, the likely consequences, and the measures taken or proposed, to the extent known. Salus will provide updates as the investigation progresses and will not delay notice to complete its investigation.
Salus will take reasonable steps to contain and remediate the incident and will provide the information Customer reasonably requires to meet its own notification obligations. Salus will not notify a regulator or affected individual on Customer's behalf without Customer's prior written direction, except where Salus is independently required to do so.
9. Government and Legal Requests
If Salus receives a subpoena, warrant, or other legal demand for Customer's Personal Data, it will, unless legally prohibited, notify Customer promptly, provide the information Customer needs to seek protective treatment, and disclose only what the demand requires.
Salus does not provide Personal Data to law enforcement voluntarily or absent valid legal process, except at Customer's direction.
10. Retention, Return, and Deletion
Salus retains Personal Data for the subscription term and as instructed by Customer. Records subject to the Clery Act generally must be retained for seven years, and Customer determines the retention period that applies to its records.
On expiration or termination, Customer may export Personal Data through the Services for at least thirty days. After that period, Salus will delete Personal Data from its systems and from backups in accordance with its documented procedures and backup cycle, unless retention is required by law or Customer instructs otherwise in writing.
Salus will confirm deletion in writing on request.
11. Audit and Assurance
On request, and no more than once per year unless required by a regulator or following a Security Incident, Salus will provide its current SOC 2 report, its completed HECVAT, a summary of its most recent penetration test, and reasonable responses to Customer's security and privacy questionnaires.
If those materials are not sufficient for Customer to verify compliance with this DPA, the parties will agree on the scope, timing, and cost of a further assessment, conducted on reasonable notice, during business hours, subject to confidentiality, and without access to other customers' data or to Salus systems in a manner that would compromise security.
12. Data Location and International Transfers
Salus Processes and stores Personal Data in the United States. Salus will not transfer Personal Data outside the United States without Customer's prior written consent.
If Customer requires Salus to Process personal data subject to the GDPR or a comparable non-United States law, the parties will execute an appropriate transfer mechanism, including standard contractual clauses, before that Processing begins.
13. Criminal Justice Information
Criminal justice information subject to the FBI CJIS Security Policy, including criminal history record information and query returns from state or federal criminal justice systems, is outside the scope of this DPA unless the parties have executed a CJIS Security Addendum and configured the Services accordingly.
Customer will notify Salus before directing the Services to ingest such information, and will notify Salus if a connected Source System begins to carry it, so that the parties can put the appropriate agreement and configuration in place.
14. General
This DPA takes effect with the Platform Agreement and continues for as long as Salus Processes Personal Data. Sections that by their nature should survive do so.
Liability under this DPA is subject to the limitations in the Platform Agreement, including the enhanced cap that applies to a Security Incident caused by Salus's failure to meet its security obligations.
Where Customer is a public institution required by law or institutional policy to apply different terms on a matter addressed here, those terms control to the extent of the conflict.
Annex A. Details of Processing
| Subject matter | Provision of the Salus compliance platform under the Platform Agreement. |
| Duration | The subscription term, plus the export and deletion periods in Section 10. |
| Nature and purpose | Ingestion, storage, analysis, classification, deduplication, statistical compilation, publication of records Customer approves, communication on Customer's behalf, audit logging, and support. |
| Categories of data subjects | Students, employees, contractors, campus security authorities, visitors, reporting parties, involved parties, witnesses, and responding personnel identified in Customer's records. |
| Types of Personal Data | Names and contact details; institutional affiliation and role; incident narratives and related case content; dates, times, and locations; disposition and classification information; training, attestation, and roster records; account identifiers, IP address, and audit log entries. Special categories may appear within narratives supplied by Customer, including information relating to health, sexual conduct, or criminal allegations. |
Annex B. Technical and Organizational Measures
- Encryption of Personal Data in transit using TLS 1.2 or higher and at rest using AES-256, with keys managed in a dedicated key management service.
- Logical tenant isolation with row level controls, so that an institution's records are accessible only to that institution's authorized members.
- Role based access control, multi-factor authentication, least privilege provisioning, and periodic access review.
- Field level access restrictions and redaction capabilities for sensitive record classes.
- Immutable audit logging of access and changes, available to Customer.
- Network segmentation, managed firewall and web application firewall, and continuous threat monitoring.
- Vulnerability scanning of code, dependencies, and infrastructure, with remediation before release, and independent penetration testing.
- Documented change management with peer review, automated testing, and staged deployment.
- Encrypted automated backups replicated across United States availability zones.
- Documented incident response plan, tested and updated periodically.
- Physical security of hosting facilities inherited from Salus's cloud infrastructure provider.
Annex C. Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, key management, and AI inference through Amazon Bedrock | United States |
| Amazon Web Services, Inc. (Amazon SES) | Delivery of platform notifications and outreach correspondence | United States |
| Resend, Inc. | Processing of inbound email sent to platform mailboxes | United States |
| Google LLC (Google Maps Platform) | Geocoding of location queries. Only the location string is sent. Narratives, personal information, and other record content are not sent. | United States |
© Salus Solutions, Inc. · Questions: privacy@trysalus.com