HumanTec Logo

Data Processing Agreement

Governing the processing of Personal Data in connection with HumanTec website, applications, AI Health Record Reader, and digital healthcare services.

DATA PROCESSING AGREEMENT

Effective Date: 06 June 2026Compliance with Sri Lanka PDPA & Healthcare Regulations

This Data Processing Agreement (“Agreement”) governs the processing of Personal Data by HumanTec Ventures (Pvt) Ltd (“HumanTec”, “we”, “us” or “our”) in connection with the HumanTec website, applications, digital healthcare services, AI Health Record Reader, teleconsultation services, care-professional services, smart healthcare solutions and related services (collectively, the “Services”).

This Agreement is intended to operate together with HumanTec’s Privacy & Safety Policy, Terms of Service, applicable consent notices and other applicable policies.

1Definitions

For the purposes of this Agreement:
  • “Personal Data” means information relating to an identified or identifiable natural person.
  • “Data Subject” means the individual to whom Personal Data relates.
  • “Controller” means the person or entity that determines the purposes and means of processing Personal Data.
  • “Processor” means a person or entity that processes Personal Data on behalf of a Controller.
  • “Special Category Personal Data” includes health and other categories of Personal Data protected as special categories under applicable data-protection law.
  • “Processing” includes collecting, recording, storing, organising, retrieving, analysing, using, transmitting, sharing, securing, deleting or otherwise handling Personal Data.
  • “Health Records” means medical reports, prescriptions, laboratory reports, diagnostic reports, images, health histories, treatment information and other information relating to a person's physical or mental health.

2Scope of Processing

HumanTec may process Personal Data in connection with:
  • 1. account creation and authentication;
  • 2. provision of healthcare and digital healthcare services;
  • 3. uploading and processing prescriptions and Health Records;
  • 4. operation of the AI Health Record Reader;
  • 5. teleconsultations and communication with care professionals;
  • 6. appointment and service management;
  • 7. customer support;
  • 8. payment and transaction processing;
  • 9. service security and fraud prevention;
  • 10. improvement, maintenance and security of the Services;
  • 11. compliance with applicable legal and regulatory obligations; and
  • 12. other purposes specifically communicated to and, where required, consented to by the Data Subject.

HumanTec shall not process Personal Data for purposes incompatible with the purposes communicated to the Data Subject, except where permitted or required by applicable law.

3Lawful Basis

HumanTec shall process Personal Data only where a lawful basis exists under applicable data-protection law. Depending on the circumstances, processing may be based on:
  • the Data Subject's consent;
  • performance of a contract or steps requested before entering into a contract;
  • compliance with a legal obligation;
  • protection of vital interests or responding to an emergency;
  • public-interest requirements where legally applicable; or
  • another lawful basis recognised under applicable law.

Where processing relies on consent, HumanTec shall obtain consent in a manner that is appropriately informed, specific and capable of being demonstrated.

4Processing of Health Information

Health information is treated by HumanTec as highly sensitive information. Where HumanTec processes Health Records or other Special Category Personal Data, HumanTec shall apply the additional requirements applicable to such information under Sri Lankan data-protection law. Where consent is the applicable legal basis, the consent shall identify the relevant purpose or purposes of processing. The upload of a Health Record shall not automatically constitute consent to unrelated processing.

5AI Health Record Reader

Where a Data Subject uploads a Health Record to the AI Health Record Reader:
  • 1. HumanTec may process the uploaded record for the specific purpose communicated at the point of upload.
  • 2. The system may extract, organise, summarise or otherwise analyse information contained in the uploaded record.
  • 3. AI-generated information is intended to provide informational or service-related assistance and shall not automatically be treated as a medical diagnosis.
  • 4. Where applicable, users shall be advised to consult a qualified healthcare professional for diagnosis, treatment or urgent medical decisions.
  • 5. HumanTec shall not use uploaded Health Records for AI model training, product development, marketing or unrelated purposes unless there is an appropriate lawful basis and, where required, separate consent or notice.
  • 6. Where HumanTec proposes to use Health Records for a materially different purpose, the relevant legal and consent requirements shall be addressed before such processing occurs.

6Data Minimisation

HumanTec shall seek to collect and process Personal Data that is adequate, relevant and proportionate to the purpose for which it is processed. Users should not upload information that is not necessary for the requested Service. Where unnecessary information is uploaded, HumanTec may take appropriate steps to restrict or delete such information, subject to applicable legal requirements.

7Accuracy

HumanTec shall take reasonable measures to maintain the accuracy and currency of Personal Data. Users are responsible for providing accurate information and should notify HumanTec where information is inaccurate, incomplete or outdated.

8Retention and Deletion

HumanTec shall retain Personal Data only for as long as reasonably necessary for the purpose for which it was collected or as required or permitted by applicable law. Retention periods may differ depending on:
  • the type of information;
  • the Service provided;
  • contractual requirements;
  • legal or regulatory requirements;
  • dispute-resolution requirements;
  • security requirements; and
  • legitimate operational requirements.

When Personal Data is no longer required, HumanTec shall take appropriate measures to delete, anonymise or securely dispose of it, subject to applicable legal obligations.

9Security Measures

HumanTec shall implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, alteration or damage. Measures may include:
  • access controls;
  • authentication controls;
  • encryption where appropriate;
  • secure storage;
  • network and application security;
  • logging and monitoring;
  • backup and recovery measures;
  • vulnerability management;
  • employee confidentiality obligations;
  • incident-response procedures;
  • pseudonymisation or anonymisation where appropriate; and
  • periodic review of security controls.

10Confidentiality

HumanTec shall ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations. Access to Health Records shall be limited to authorised personnel and systems with a legitimate operational requirement.

11Third-Party Processors

HumanTec may engage carefully selected third-party service providers to support the Services. Such providers may include:
  • cloud-hosting providers;
  • IT infrastructure providers;
  • payment service providers;
  • communications providers;
  • cybersecurity providers;
  • analytics providers;
  • customer-support providers;
  • healthcare-service providers; and
  • other technology or operational service providers.

HumanTec shall take appropriate measures to ensure that processors process Personal Data only for authorised purposes and maintain appropriate safeguards.

12Sub-Processors

Where a third-party processor appoints another processor to process Personal Data on HumanTec's behalf, appropriate contractual and security safeguards shall be applied as required by applicable law. HumanTec shall maintain appropriate oversight of relevant processors and sub-processors.

13Cross-Border Processing

Personal Data may be processed or stored outside Sri Lanka where permitted by applicable law. Where cross-border processing or transfer occurs, HumanTec shall implement the safeguards and conditions required under the applicable Sri Lankan data-protection framework, including requirements introduced or amended by the Personal Data Protection (Amendment) Act No. 22 of 2025. Where explicit consent is required for a proposed cross-border transfer, HumanTec shall obtain such consent after providing the information required by law, including relevant risks.

14Data Breaches and Security Incidents

HumanTec shall maintain procedures for identifying, investigating, containing and responding to Personal Data breaches and security incidents. Where a breach triggers notification obligations under applicable law, HumanTec shall make the required notifications within the applicable statutory timeframe. Where appropriate, affected Data Subjects may also be informed of a relevant breach in accordance with applicable law.

15Data Subject Rights

Subject to applicable law and relevant limitations, Data Subjects may have rights including:
  • access to their Personal Data;
  • withdrawal of consent where processing is based on consent;
  • rectification or completion of inaccurate or incomplete information;
  • erasure in circumstances provided by law;
  • restriction or objection to certain processing;
  • review of certain decisions based solely on automated processing; and
  • other rights provided under applicable data-protection law.

HumanTec shall maintain mechanisms through which Data Subjects can exercise applicable rights.

16Identity Verification

To protect Personal Data from unauthorised access, HumanTec may take reasonable steps to verify the identity or authority of a person submitting a Data Subject request. HumanTec may refuse or limit a request where permitted by applicable law.

17Children and Minors

HumanTec shall apply appropriate safeguards when processing Personal Data relating to children or minors. Where applicable law requires parental or legal-guardian consent, HumanTec shall require such consent before processing the relevant information.

18Automated Processing and AI

HumanTec may use automated systems and AI technologies to provide certain Services. Where applicable, HumanTec shall implement safeguards required by law concerning automated decision-making. AI-generated information shall not be represented as infallible and may require verification by an appropriately qualified healthcare professional.

19Data Protection Management

HumanTec shall maintain appropriate internal policies, procedures, records, safeguards and governance measures proportionate to the nature, scale and sensitivity of its processing activities. Where required by applicable law, HumanTec shall conduct appropriate data-protection impact assessments and maintain a Data Protection Management Programme.

20Cooperation

HumanTec shall take reasonable steps to cooperate with competent regulatory authorities and respond appropriately to lawful requests relating to Personal Data processing.

21Changes to this Agreement

HumanTec may update this Agreement where necessary to reflect changes in:
  • applicable law;
  • regulatory requirements;
  • technology;
  • Services;
  • security practices; or
  • business operations.

Material changes shall be communicated through appropriate channels where required.

22Governing Law

This Agreement shall be governed by the laws of Sri Lanka, unless another governing law is required or permitted under applicable law.

23Contact Information

For questions, complaints or requests relating to Personal Data processing, users may contact:
  • Company: HumanTec Ventures.
  • Website: www.humantec.lk
  • Email: info@humantec.lk
  • Data Protection Officer Email: info@humantec.lk
  • Address: No. 14/2 D.S. Senanayake Mawatha, Borella, Colombo, Sri Lanka.
Elderly couple care banner background

Give them the care they deserve, even when you can't be there.

Your loved ones' safety shouldn't be a source of worry. With one-tap SOS alerts, 24/7 doctor consultations, and a built-in pharmacy, we provide a complete safety net for your parents, right from your phone.

Try a Consultation