We use local storage to remember your preferences and measure audience anonymously (Vercel Analytics — no personal data collected). Privacy Policy
GDPR Article 28 — for institutional subscribers
Effective date: June 24, 2026
Request a Signed Copy
To obtain a countersigned copy of this DPA for your institutional procurement records, contact us. We respond within 2 business days with a countersigned PDF.
Controller: The organization subscribing to HealthWatch Global services (hereinafter "Controller").
Processor: HealthWatch Global, operated by David Deheunynck, sole trader (France) (hereinafter "Processor"). This DPA forms part of the Terms of Service and governs all processing of personal data by the Processor on behalf of the Controller.
The Processor provides the Controller's authorized users with access to HealthWatch Global, a real-time epidemic surveillance dashboard. In doing so, the Processor processes personal data on behalf of the Controller as set out in this DPA.
| Category | Detail | Data Subjects |
|---|---|---|
| Account credentials | Email address, hashed password | Controller's authorized users |
| Profile data | Name, organization, role (if provided) | Controller's authorized users |
| Alert preferences | Monitored regions, diseases, language | Controller's authorized users |
| Usage data | Login timestamps, features accessed | Controller's authorized users |
| Billing data | Billing email, organization name (payment card data processed directly by Stripe) | Billing contact |
The Controller grants general authorization to engage the following sub-processors. The Processor will notify the Controller of any intended changes, giving the Controller the opportunity to object.
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database & authentication | UE — Frankfurt (Allemagne) | AWS eu-central-1 · DPA Supabase |
| Sendinblue SAS (Brevo) | Transactional email & alerts | UE — Paris (France) | Entreprise française · RGPD natif |
| Vercel Inc. | Hosting & CDN | CDN mondial (edge UE dispo) | SCCs · EU region configurable |
| Stripe Inc. | Payment processing | UE / États-Unis | DPA Stripe · SCCs transferts US |
In the event of a personal data breach, the Processor shall notify the Controller without undue delay and, where feasible, not later than 24 hours after becoming aware. The notification shall include all information required under Article 33(3) GDPR.
This DPA is effective for the duration of the HealthWatch Global subscription. Upon termination, the Processor shall delete or return all personal data within 30 days, provide a CSV export upon request before deletion, and delete all existing copies unless retention is required by applicable law.
This DPA is governed by French law and Regulation (EU) 2016/679 (GDPR). Any dispute shall be subject to the exclusive jurisdiction of the courts of Paris, France.
Request a Signed Copy
To obtain a countersigned copy of this DPA for your institutional procurement records, contact us. We respond within 2 business days with a countersigned PDF.