Data Processing Addendum
United States
Effective date: August 9, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (“Customer,” the business/controller) and Aku Online Limitedtrading as DoulaOne (“DoulaOne,” “we,” the service provider/processor). It applies to personal information DoulaOne processes on your behalf about your clients under US state consumer-privacy laws, including the California Consumer Privacy Act as amended by the CPRA (“CCPA”) and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states (together, “US Privacy Laws”). By using DoulaOne to process personal information about your clients, you agree to this DPA. Capitalized terms not defined here have the meaning given in the applicable US Privacy Laws.
1. Roles of the parties
For personal information you enter about your clients and their families (“Customer Personal Information”), you are the business (controller) and DoulaOne is your service provider (processor). DoulaOne is an independent business for its own account data, as described in our Privacy Policy.
2. Purpose and scope of processing
- Subject matter: provision of the DoulaOne practice-management platform.
- Duration: for the term of your account, plus any limited retention described in Section 8.
- Business purpose: storing, organizing, displaying, transmitting, and deleting Customer Personal Information to operate the Service for you.
- Types of information: contact details, due dates, appointments, care and clinical notes, birth preferences, contracts and e-signatures (including signer IP address and browser/user-agent captured for signature audit), intake responses, invoices and payment references, messages, and uploaded documents.
- Data subjects: your clients, their partners, family members, and emergency contacts.
- Sensitive information: health-related and other sensitive information you choose to store.
3. Service provider commitments (CCPA / CPRA)
We process Customer Personal Information only on your behalf and for the business purposes above and in the Terms. We will:
- Not sell or share Customer Personal Information (as “sell” and “share” are defined under the CCPA).
- Not retain, use, or disclose Customer Personal Information for any purpose other than the business purposes specified in the Terms, or as otherwise permitted by the CCPA, including outside the direct business relationship between us.
- Not combine Customer Personal Information with personal information we receive from other sources, except as permitted by the CCPA.
- Comply with the obligations applicable to service providers under US Privacy Laws and provide the same level of privacy protection they require.
- Notify you if we determine we can no longer meet our obligations under US Privacy Laws, and, if so, allow you to take reasonable steps to stop and remediate unauthorized use.
- Grant you the right to take reasonable and appropriate steps to ensure we use Customer Personal Information in a manner consistent with your obligations under US Privacy Laws.
We hereby certify that we understand these restrictions and will comply with them.
4. Your responsibilities
You are responsible for: (a) having a lawful basis to collect and process Customer Personal Information; (b) providing your clients with required privacy notices and obtaining any required consents; (c) ensuring your instructions to us comply with US Privacy Laws; and (d) the accuracy, quality, and legality of Customer Personal Information and the means by which you acquired it. Your use of the platform's features constitutes your instructions for processing.
5. Confidentiality and personnel
We ensure that personnel authorized to process Customer Personal Information are bound by appropriate confidentiality obligations and access the information only as needed to provide and support the Service.
6. Security measures
We implement and maintain reasonable technical and organizational security measures designed to protect Customer Personal Information, including:
- Row-level security isolating each workspace's data
- Private, access-controlled file storage with signed URLs
- Encryption in transit (HTTPS/TLS)
- Server-side authentication and access controls
- Restricted access to production systems and secrets
7. Subcontractors (subprocessors)
You authorize us to engage the subcontractors below to help provide the Service. Each is bound by written terms requiring the same level of privacy protection as this DPA and permitting them to process Customer Personal Information only on our behalf.
- Supabase— database, authentication, and file storage (EU, Paris region)
- Vercel— application and website hosting
- Brevo— transactional and (where recipients opt in) marketing email delivery
- Stripe— payment processing, where you enable online client payments (only if you connect it)
- Mapbox— map display on public directory pages
- Google— optional Sign-in and Calendar / Meet integration (only if you connect it)
- Zoom— optional meeting links for appointments (only if you connect it)
- Calendly— optional booking import (only if you connect it)
- OpenAI— optional AI assists (only if you enable them)
We will give notice of any intended addition or replacement of a subcontractor by updating this page and, where you have subscribed to notices, by email. You may object on reasonable data-protection grounds by contacting contact@doulaone.com; if we cannot accommodate your objection, you may stop using the affected feature or terminate.
8. Consumer requests and assistance
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to verifiable consumer requests under US Privacy Laws (to know/access, delete, correct, or obtain a portable copy of personal information), including through in-app export and deletion tools and by support where needed. If we receive a consumer request directed to Customer Personal Information, we will, where permitted by law, refer the consumer to you or forward the request to you rather than responding directly.
9. Security incidents
We will notify you without undue delay after becoming aware of a breach of security leading to the unauthorized acquisition of Customer Personal Information, and provide information reasonably available to help you meet your own notification obligations under applicable breach-notification laws. Notice of an incident is not an acknowledgment of fault or liability.
10. Return and deletion
You can export and delete Customer Personal Information through the platform at any time. On termination of your account, we will delete or return Customer Personal Information within a reasonable period, except where retention is required by law. Backups are deleted on our routine backup-expiry cycle.
We may create and retain aggregated or de-identified data that no longer identifies any individual (for example, statistical or performance insights), and may continue to use such data after termination to operate and improve the Service. This data is not Customer Personal Information.
11. Verification and audits
We will make available information reasonably necessary to demonstrate our compliance with this DPA and, on reasonable prior request and subject to confidentiality, respond to your reasonable audit inquiries (including, where available, through third-party certifications or reports from our subcontractors).
12. HIPAA
DoulaOne is not a HIPAA business associate and does not sign Business Associate Agreements. This DPA does not constitute a BAA. If your practice is subject to HIPAA, do not store protected health information in the Service unless and until we have agreed a BAA in writing.
13. International data and EU/UK data subjects
Customer Personal Information is primarily stored in the European Union (Supabase, Paris). If your processing also involves personal data protected by the EU or UK GDPR, our GDPR Data Processing Agreement applies to that data in addition to this DPA, including its international-transfer safeguards.
14. Changes to this DPA
We may update this DPA from time to time to reflect changes in the Service, our subcontractors, or legal requirements. We will post the revised version on this page and update the effective date, and for material changes will provide notice through the Service or by email where appropriate.
15. Liability and precedence
This DPA is subject to the limitations and exclusions of liability set out in the Terms. If there is a conflict between this DPA and the Terms regarding the processing of Customer Personal Information, this DPA prevails.
16. Contact
For data-protection inquiries, subcontractor objections, or to request a signed copy of this DPA:
See also our Privacy Policy and Terms of Service.
