Legal

Data Processing Addendum

audit the outcome · verify activation · prove it every Friday

This DPA forms part of the Master Subscription Agreement and governs the processing of Personal Data by Luminex Global Inc. on Customer's behalf under the GDPR, CCPA, and analogous laws.

Last updated April 2026

Plain-language summary

Customer is the Controller. Luminex Global Inc. is the Processor. We process Customer's Personal Data only on documented instructions, only to deliver the Riley service. We do not sell data, do not train AI on it, and retain it only as needed. We support Customer in honoring data-subject rights within legal SLAs. Subprocessors are disclosed at Disclosures section 18; material changes are notified 30 days in advance.

1. Roles

Customer is the Controller (or Business under CCPA). Luminex Technologies LLC is the Processor (or Service Provider under CCPA). Where Customer's underlying data subjects include patients, Customer is also the Covered Entity under HIPAA and a parallel BAA applies. See the HIPAA Notice.

2. Scope and instructions

Luminex processes Personal Data only to deliver the Riley service to Customer per the MSA. Categories of Personal Data: practice contact info, patient identifiers (where authorized), and review, AR, and recall content. Categories of data subjects: Customer's staff and Customer's patients (where authorized). Processing duration: subscription term plus 90 days for export.

3. Confidentiality and staff

All Luminex personnel with access to Personal Data are bound by confidentiality obligations and least-privilege role-based access controls.

4. Security measures

Technical and organizational measures listed on the Security page: encryption at rest (AES-256), encryption in transit (TLS 1.3), OAuth-only authentication, per-tenant isolation, automatic PII scanning, immutable audit logs, and SOC 2 readiness work (not certification).

5. Subprocessors

Customer authorizes the use of subprocessors listed in Disclosures section 18. Material changes are posted 30 days in advance. Each subprocessor is bound by data-protection terms consistent with this DPA.

6. Data subject rights

Luminex assists Customer in honoring data subject rights (access, deletion, correction, portability, objection) within applicable legal SLAs: 30 days for HIPAA and GDPR, 45 days for CCPA. Customer initiates requests via privacy@hireriley.com.

7. International transfers

Customer Personal Data is processed in the United States. For EU and UK transfers (when applicable), Luminex relies on the EU Standard Contractual Clauses 2021/914 (Module 2: Controller-to-Processor) and the UK International Data Transfer Addendum.

8. Audits

Customer may audit Luminex's compliance with this DPA on 30 days' notice, no more than once per 12 months, at Customer's expense, subject to confidentiality. SOC 2 reports satisfy audit obligations once issued.

9. Breach notification

Luminex notifies Customer of Personal Data breaches without undue delay and within 72 hours of becoming aware as required by GDPR Article 33. Notification includes the nature of the breach, categories and approximate number affected, likely consequences, and remediation steps.

10. Termination and deletion

Upon termination, Customer has 90 days to export Personal Data. After 90 days, Luminex deletes or returns Personal Data per Customer instruction. Backup data follows 90-day rolling retention and is then purged. Aggregated, fully anonymized data is not subject to deletion.


DPA template for execution at signup or on request: legal@hireriley.com. See also Terms, Privacy, HIPAA Notice, Security, and Disclosures.