Data Processing Agreement
Governing the processing of Personal Data in connection with HumanTec website, applications, AI Health Record Reader, and digital healthcare services.
DATA PROCESSING AGREEMENT
This Data Processing Agreement (“Agreement”) governs the processing of Personal Data by HumanTec Ventures (Pvt) Ltd (“HumanTec”, “we”, “us” or “our”) in connection with the HumanTec website, applications, digital healthcare services, AI Health Record Reader, teleconsultation services, care-professional services, smart healthcare solutions and related services (collectively, the “Services”).
This Agreement is intended to operate together with HumanTec’s Privacy & Safety Policy, Terms of Service, applicable consent notices and other applicable policies.
1Definitions
- “Personal Data” means information relating to an identified or identifiable natural person.
- “Data Subject” means the individual to whom Personal Data relates.
- “Controller” means the person or entity that determines the purposes and means of processing Personal Data.
- “Processor” means a person or entity that processes Personal Data on behalf of a Controller.
- “Special Category Personal Data” includes health and other categories of Personal Data protected as special categories under applicable data-protection law.
- “Processing” includes collecting, recording, storing, organising, retrieving, analysing, using, transmitting, sharing, securing, deleting or otherwise handling Personal Data.
- “Health Records” means medical reports, prescriptions, laboratory reports, diagnostic reports, images, health histories, treatment information and other information relating to a person's physical or mental health.
2Scope of Processing
- 1. account creation and authentication;
- 2. provision of healthcare and digital healthcare services;
- 3. uploading and processing prescriptions and Health Records;
- 4. operation of the AI Health Record Reader;
- 5. teleconsultations and communication with care professionals;
- 6. appointment and service management;
- 7. customer support;
- 8. payment and transaction processing;
- 9. service security and fraud prevention;
- 10. improvement, maintenance and security of the Services;
- 11. compliance with applicable legal and regulatory obligations; and
- 12. other purposes specifically communicated to and, where required, consented to by the Data Subject.
HumanTec shall not process Personal Data for purposes incompatible with the purposes communicated to the Data Subject, except where permitted or required by applicable law.
3Lawful Basis
- the Data Subject's consent;
- performance of a contract or steps requested before entering into a contract;
- compliance with a legal obligation;
- protection of vital interests or responding to an emergency;
- public-interest requirements where legally applicable; or
- another lawful basis recognised under applicable law.
Where processing relies on consent, HumanTec shall obtain consent in a manner that is appropriately informed, specific and capable of being demonstrated.
4Processing of Health Information
5AI Health Record Reader
- 1. HumanTec may process the uploaded record for the specific purpose communicated at the point of upload.
- 2. The system may extract, organise, summarise or otherwise analyse information contained in the uploaded record.
- 3. AI-generated information is intended to provide informational or service-related assistance and shall not automatically be treated as a medical diagnosis.
- 4. Where applicable, users shall be advised to consult a qualified healthcare professional for diagnosis, treatment or urgent medical decisions.
- 5. HumanTec shall not use uploaded Health Records for AI model training, product development, marketing or unrelated purposes unless there is an appropriate lawful basis and, where required, separate consent or notice.
- 6. Where HumanTec proposes to use Health Records for a materially different purpose, the relevant legal and consent requirements shall be addressed before such processing occurs.
6Data Minimisation
7Accuracy
8Retention and Deletion
- the type of information;
- the Service provided;
- contractual requirements;
- legal or regulatory requirements;
- dispute-resolution requirements;
- security requirements; and
- legitimate operational requirements.
When Personal Data is no longer required, HumanTec shall take appropriate measures to delete, anonymise or securely dispose of it, subject to applicable legal obligations.
9Security Measures
- access controls;
- authentication controls;
- encryption where appropriate;
- secure storage;
- network and application security;
- logging and monitoring;
- backup and recovery measures;
- vulnerability management;
- employee confidentiality obligations;
- incident-response procedures;
- pseudonymisation or anonymisation where appropriate; and
- periodic review of security controls.
10Confidentiality
11Third-Party Processors
- cloud-hosting providers;
- IT infrastructure providers;
- payment service providers;
- communications providers;
- cybersecurity providers;
- analytics providers;
- customer-support providers;
- healthcare-service providers; and
- other technology or operational service providers.
HumanTec shall take appropriate measures to ensure that processors process Personal Data only for authorised purposes and maintain appropriate safeguards.
12Sub-Processors
13Cross-Border Processing
14Data Breaches and Security Incidents
15Data Subject Rights
- access to their Personal Data;
- withdrawal of consent where processing is based on consent;
- rectification or completion of inaccurate or incomplete information;
- erasure in circumstances provided by law;
- restriction or objection to certain processing;
- review of certain decisions based solely on automated processing; and
- other rights provided under applicable data-protection law.
HumanTec shall maintain mechanisms through which Data Subjects can exercise applicable rights.
16Identity Verification
17Children and Minors
18Automated Processing and AI
19Data Protection Management
20Cooperation
21Changes to this Agreement
- applicable law;
- regulatory requirements;
- technology;
- Services;
- security practices; or
- business operations.
Material changes shall be communicated through appropriate channels where required.
22Governing Law
23Contact Information
- Company: HumanTec Ventures.
- Website: www.humantec.lk
- Email: info@humantec.lk
- Data Protection Officer Email: info@humantec.lk
- Address: No. 14/2 D.S. Senanayake Mawatha, Borella, Colombo, Sri Lanka.

Give them the care they deserve, even when you can't be there.
Your loved ones' safety shouldn't be a source of worry. With one-tap SOS alerts, 24/7 doctor consultations, and a built-in pharmacy, we provide a complete safety net for your parents, right from your phone.
Try a Consultation