This Data Processing Agreement ("DPA") is entered into between Warp Speed Solutions Inc., a Flexio Holding Inc company, a corporation organized under the laws of Puerto Rico ("Routina," "Processor") and the customer identified in the applicable Order Form or account ("Customer," "Controller"). This DPA forms part of the agreement between Routina and Customer (the "Agreement") and applies to the processing of personal data in connection with the Routina Service.
1. Definitions
- "Controller" means the entity that determines the purposes and means of processing personal data — in most cases, the Customer.
- "Processor" means the entity that processes personal data on behalf of the Controller — in this context, Routina.
- "Data Subject" means the identified or identifiable natural person to whom personal data relates.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under the GDPR, CCPA, or other applicable privacy law.
- "Processing" means any operation performed on personal data, including collection, recording, storage, use, disclosure, erasure, or destruction.
- "Protected Health Information" (PHI) means individually identifiable health information as defined under HIPAA.
- "Sensitive Data" means categories of personal data that warrant heightened protection, including health data, financial data, government-issued identifiers, and biometric data.
- "Subprocessor" means any third party engaged by Routina to process personal data on Routina's behalf in connection with the Service.
- "GDPR" means the General Data Protection Regulation (EU) 2016/679.
- "CCPA" means the California Consumer Privacy Act.
- "HIPAA" means the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations.
- "SCCs" means Standard Contractual Clauses approved by the European Commission for international data transfers.
- "AI Features" means features of the Service that use large language models or other machine learning systems, including assistants, autonomous agents, and automated classification, extraction, or drafting.
- "Model Provider" means a third party that provides model inference used by AI Features.
- "Customer-Provided Key" means an API key or credential for a Model Provider that the Customer supplies to the Service so that AI Features run under the Customer's own account with that provider.
2. Scope and Role of the Parties
This DPA applies to Routina's processing of personal data on behalf of the Customer in connection with the provision of the Service. The Customer acts as the Controller (or Business under CCPA) and Routina acts as the Processor (or Service Provider under CCPA).
It applies to every environment through which Routina provides the Service — including app.routina.tech, partners.routina.tech, and any other domain, dedicated environment, or regional deployment Routina operates from time to time. Each environment runs on separate infrastructure with its own database, and personal data is not shared between them; the obligations in this DPA apply identically to each.
The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects relevant to the processing are as follows:
- Subject matter: Provision of the Routina AI orchestration platform
- Duration: For the term of the Agreement and as required for legal retention obligations
- Nature and purpose: Automated processing, storage, and orchestration of operational data across connected systems to enable AI-driven workflow automation, including transmission of Customer-configured inputs to Model Providers for inference as described in Section 8
- Types of personal data: Contact information, scheduling data, patient or client records (as configured by the Customer), operational logs, and any other data the Customer chooses to connect via integrations
- Categories of data subjects: Customer's employees, contractors, patients, clients, end-users, and third parties whose data is processed through connected systems
3. Customer Obligations
The Customer represents and warrants that:
- It has a valid legal basis for processing personal data and for instructing Routina to process it on its behalf
- It has obtained all necessary consents, authorizations, and permissions from data subjects required to process and share their data with Routina
- It has provided data subjects with appropriate privacy notices that contemplate processing by Routina as a service provider
- Its instructions to Routina regarding data processing comply with all applicable laws
- It will notify Routina promptly if it becomes aware of any data subject complaint, regulatory inquiry, or potential data breach affecting data processed through the Service
4. Routina's Obligations as Processor
Routina agrees to:
- Process personal data only on documented instructions from the Customer, unless required to do so by applicable law
- Ensure that all personnel authorized to process personal data are bound by confidentiality obligations
- Implement and maintain appropriate technical and organizational security measures as described in Section 9
- Assist the Customer in meeting its obligations regarding data subject rights requests as described in Section 6
- Assist the Customer with data protection impact assessments (DPIAs) where required under Article 35 GDPR
- Delete or return all personal data to the Customer upon termination of the Agreement, as described in Section 13
- Provide all information necessary to demonstrate compliance with obligations under this DPA and applicable law
- Not engage any Subprocessor without prior Customer authorization, except as set forth in Section 7
5. Processing Instructions
Routina processes personal data solely in accordance with the Customer's documented instructions, which are set out in the Agreement, the Order Form, and any additional written instructions provided by the Customer. Routina will promptly notify the Customer if it believes any instruction violates applicable law.
Where Routina is required by applicable law to process personal data other than as instructed, Routina will notify the Customer of that legal requirement before processing (unless the law prohibits such notification on grounds of public interest).
6. Data Subject Rights
Routina will assist the Customer, using appropriate technical and organizational measures, in fulfilling its obligations to respond to data subject requests to exercise rights under applicable law, including:
- Right of access to personal data
- Right to rectification of inaccurate or incomplete data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Rights related to automated decision-making and profiling
Where Routina receives a data subject request directly, it will promptly forward the request to the Customer and refrain from responding to the data subject directly unless authorized by the Customer or required by law.
7. Subprocessors
The Customer provides general authorization for Routina to engage Subprocessors in connection with the Service. Routina will: (a) enter into a written agreement with each Subprocessor imposing data protection obligations at least as stringent as those in this DPA; and (b) remain liable to the Customer for the performance of each Subprocessor's obligations.
Routina maintains its current list of Subprocessors at getroutina.com/subprocessors, which is incorporated into this DPA and is the authoritative version. The table below reproduces that list as of the effective date of this DPA. Routina will notify the Customer of any intended addition or replacement at least 30 days in advance, giving the Customer the opportunity to object. Customers may subscribe to change notices by emailing privacy@getroutina.com. If the Customer objects on reasonable data protection grounds and the parties cannot resolve the issue, the Customer may terminate the affected services and receive a prorated refund of prepaid fees for the unused period.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure, hosting, storage, database | United States |
| Anthropic, PBC | AI language model inference (Claude) | United States |
| OpenAI, L.L.C. | AI language model inference, where selected by the Customer | United States |
| Stripe, Inc. | Payment processing and subscription billing | United States |
| Twilio Inc. | SMS and voice communications | United States |
| Twilio SendGrid | Transactional and notification email delivery | United States |
| Resend, Inc. | Transactional and notification email delivery | United States |
| Cloudflare, Inc. | Content delivery, network security, bot detection (Turnstile) | United States, global edge network |
| Slack Technologies, LLC | Internal operational notifications and alerts | United States |
| Google LLC | Google Workspace integrations, where connected by the Customer | United States |
| what3words Limited | Location reference lookup, where the feature is enabled | United Kingdom |
| Webflow, Inc. | Public marketing website hosting (no customer platform data) | United States |
Some Subprocessors are engaged only where the Customer enables the corresponding feature or Integration, as noted in the Purpose column. A Model Provider accessed through a Customer-Provided Key is not a Routina Subprocessor — see Section 8(c).
8. AI Processing and Model Providers
a. No Training on Customer Data
Routina does not use personal data processed on the Customer's behalf, nor any inputs or outputs of AI Features, to train, fine-tune, or otherwise develop machine learning models — whether Routina's own or a third party's. This is a processing restriction under Section 5 and is not subject to change without an amendment to this DPA.
b. Model Providers Engaged by Routina
Where Routina engages a Model Provider on the Customer's behalf, that provider is a Subprocessor under Section 7 and is bound by a written agreement meeting the requirements of that Section. Routina contracts for zero-retention or no-training handling where the Model Provider makes such terms available, and identifies on the subprocessor page which providers those terms are in place with. Inputs are transmitted for the purpose of generating a response and for no other purpose instructed by Routina.
c. Customer-Provided Keys
Where the Customer supplies a Customer-Provided Key, the Customer instructs Routina to transmit inputs to that Model Provider under the Customer's own account. In that configuration:
- The Model Provider is not a Routina Subprocessor for those requests, and Section 7 does not apply to it. The Customer is responsible for its own agreement with that provider, including any data processing terms or BAA it requires.
- Routina's role is limited to transmitting the inputs as instructed. Routina does not control, and is not liable for, that provider's retention, security, availability, or use of the data it receives.
- The Customer is responsible for confirming that the provider's terms satisfy the Customer's obligations as Controller, including in respect of international transfers and any Sensitive Data or PHI involved.
d. Limits of Routina's Commitment
Model Providers determine their own retention, abuse-monitoring, and model-improvement policies, and those policies may change. Routina selects providers with care and contracts for the strongest terms available to it, but cannot audit or warrant a third party's internal handling of data. To the maximum extent permitted by applicable law, Routina is not liable for a Model Provider's use, retention, or disclosure of data, or for changes to that provider's policies. Nothing in this paragraph limits Routina's liability for its own selection and oversight of Subprocessors under Section 7.
e. Automated Decision-Making
Where the Customer configures AI Features to produce or inform decisions about individuals, the Customer is the Controller of that processing and is responsible for its lawfulness, including any requirement for human involvement, transparency, or a data protection impact assessment. Routina will assist the Customer with such assessments as described in Section 4. Output may be inaccurate and must not be treated as verified fact.
9. Security Measures
Routina maintains an information security program designed to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage, appropriate to the nature of the data and the size and stage of Routina's business. The program is aligned to the NIST Cybersecurity Framework at approximately Tier 2 (Risk Informed): security practices are approved by management, prioritized against identified risk, and applied consistently across the organization, while formal organization-wide policy and continuous measurement remain under development. Routina reviews the program at least annually and works toward higher maturity as the business grows.
The program includes, but is not limited to:
- Encryption: Personal data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256)
- Access controls: Role-based access control (RBAC), multi-factor authentication for internal systems, and administration on the principle of least privilege
- Audit logging: Agent actions, data access, and configuration changes are logged with timestamps and user attribution
- Network security: Firewalls, network segmentation, monitoring of the production environment, and vulnerability scanning
- Vendor management: Security review of Subprocessors and contractual security requirements
- Personnel: Confidentiality obligations for all personnel with access to personal data, and privacy and security training
- Business continuity: Backup procedures and documented restoration and disaster recovery practices
- Security testing: Periodic security assessment of the Service, including third-party testing where appropriate to the risk
Routina may update these measures as technology and risk evolve, provided it does not materially reduce the overall level of protection. Customers may request a current description of Routina's technical and organizational measures under Section 14.
10. Personal Data Breach Notification
Where Routina determines that a personal data breach affecting Customer personal data has occurred, Routina will notify the Customer without undue delay after that determination, and in any event within the timeframe required by applicable law, so that the Customer can meet its own notification obligations as Controller. Routina will use reasonable efforts to provide that notice within 72 hours of determining that a reportable breach has occurred.
Routina will provide the Customer with the information reasonably available to it at the time, including, to the extent known: (a) the nature of the breach; (b) the categories and approximate number of data subjects affected; (c) the categories and approximate volume of personal data records affected; (d) the likely consequences; and (e) the measures taken or proposed to address it.
Routina will cooperate with the Customer and take reasonable steps to investigate, mitigate, and remediate the breach. The Customer acknowledges that initial information is often incomplete and that assessment of an incident takes time; Routina will provide further detail as it becomes available rather than delaying initial notice, and an initial notice is not an admission of fault or of liability. Where an executed BAA applies, its incident reporting terms govern PHI-related incidents to the extent they are more specific.
11. HIPAA and Business Associate Agreement
Where the Customer is a "covered entity" or "business associate" as defined under HIPAA and uses the Routina Service to create, receive, maintain, or transmit Protected Health Information (PHI), the parties must execute a separate Business Associate Agreement (BAA) prior to any such use.
Routina's Service infrastructure is designed to support HIPAA compliance requirements, including:
- Administrative, physical, and technical safeguards for PHI as required under the HIPAA Security Rule
- Full audit trail logging of all access to and actions involving PHI
- Minimum necessary access controls limiting PHI exposure to what is required for service delivery
- Procedures for reporting security incidents involving PHI within the timeframes required by the HIPAA Breach Notification Rule
Any aggregate or statistical information Routina derives from data that includes PHI will be created only from information de-identified in accordance with 45 C.F.R. § 164.514(b), by expert determination or the Safe Harbor method, and Routina will not attempt to re-identify it. Routina does not use PHI to train, fine-tune, or develop machine learning models, consistent with Section 8(a).
To request a BAA, contact legal@getroutina.com. Do not transmit PHI through the Service until a signed BAA is in place. Transmitting PHI without an executed BAA is a material breach of the Agreement and may result in immediate suspension under Section 4.4 of the Terms of Service.
12. International Data Transfers
Routina is based in Puerto Rico, United States. Personal data processed through the Service may be transferred to and stored in the United States. Where the Customer is located in the EEA, UK, or another jurisdiction with data transfer restrictions, Routina relies on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs): EU Commission-approved SCCs for transfers of EEA personal data to third countries
- UK International Data Transfer Addendum: For transfers from the United Kingdom
- Other lawful mechanisms: As applicable and as agreed between the parties
Customers in the EEA, UK, or Switzerland may request execution of SCCs by contacting privacy@getroutina.com.
13. Data Retention and Deletion
Routina retains personal data for the duration of the Agreement and as necessary to fulfill legal, regulatory, or contractual obligations. Upon termination of the Agreement:
- Routina will, at the Customer's election, return or securely delete all personal data processed on the Customer's behalf within 90 days of termination
- Routina will provide written confirmation of deletion upon Customer's request
- Backups containing personal data will be purged in accordance with Routina's backup rotation schedule, not to exceed 90 days from the deletion request
- Where retention is required by applicable law, Routina will retain the minimum data necessary and notify the Customer
14. Audits and Assessments
Routina will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. Upon reasonable written notice (no less than 30 days), Routina will permit the Customer or its authorized representative to conduct audits or inspections related to Routina's processing of Customer personal data, subject to confidentiality obligations and the following conditions:
- Audits will be conducted during normal business hours and in a manner that minimizes disruption to Routina's operations
- The Customer bears the cost of any audit unless the audit reveals a material breach of this DPA
- Audits may be conducted no more than once per calendar year, except where required by a supervisory authority or following a confirmed data breach
- Routina may satisfy audit requests through provision of third-party security certifications or audit reports (e.g., SOC 2 Type II) where available
15. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions set out in Section 12 of the Terms of Service, and the cap in that Section is a single aggregate cap covering claims under the Agreement, this DPA, and any executed Business Associate Agreement taken together. Claims under this DPA do not create a separate or additional cap.
Nothing in this DPA limits either party's liability where such limitation is not permitted by applicable data protection law, including liability to data subjects under Article 82 GDPR.
16. Term and Termination
This DPA is effective from the date the Customer accepts the Agreement and continues until the termination of the Agreement. Termination of the Agreement shall automatically terminate this DPA. Provisions that by their nature survive termination — including obligations related to data deletion, confidentiality, and liability — will remain in effect following termination.
17. Contact and Execution
For data protection inquiries, requests to execute SCCs, or to initiate a Business Associate Agreement, please contact:
Warp Speed Solutions Inc., a Flexio Holding Inc company (Routina) — Data Protection
Privacy & DPA inquiries: privacy@getroutina.com
Legal & BAA requests: legal@getroutina.com
Built in Puerto Rico, United States