Data Protection Addendum | HANUMANIT
Data Protection Addendum (DPA)
Last updated: 6 October 2026
1. Introduction
This Data Protection Addendum ("Addendum") forms part of the Hanuman IT Co., Ltd. Privacy Policy and Terms of Use, and any service agreement between Hanuman IT and its clients (collectively, the "Agreement"). It applies where and only to the extent that Hanuman IT processes Customer Data subject to Data Protection Laws on behalf of clients as a Data Processor while providing the Service.
2. Definitions
- "Account Users" means any individual accessing and/or using the Service through the client's account as authorized by the client.
- "Hanuman IT" means Hanuman IT Co., Ltd. (company registration no. 0345558000799).
- "Customer Data" means any Personal Data that Hanuman IT processes as a Data Processor on behalf of the client.
- "Data Controller" means the entity which determines the purposes and means of the processing of Personal Data. Clients are the Data Controllers of Customer Data.
- "Data Processor" means the entity which processes Personal Data on behalf of the Data Controller. Hanuman IT is the Data Processor of Customer Data.
- "Data Protection Laws" means the Thailand Personal Data Protection Act B.E. 2562 (PDPA) and, to the extent applicable, the EU General Data Protection Regulation (GDPR).
- "Request" means a written request from a Data Subject to exercise their rights under Data Protection Laws.
- "Service" means Hanuman IT's software and web-based applications for hospital pathology laboratory information management and result reporting (e.g. anatomical/digital pathology systems), including customization, implementation, maintenance and after-sales support.
- "Sub-processor" means any Data Processor engaged by Hanuman IT to assist in providing the Service.
3. Processing of Personal Data
Roles. Clients are the Data Controllers of Customer Data, and Hanuman IT processes Customer Data only as a Data Processor acting on the client's documented instructions, including processing initiated by Account Users.
Client obligations. Clients shall (i) comply with their obligations as Data Controllers; (ii) maintain adequate privacy notices for every channel that connects to the Service; and (iii) provide notices, respond to rights requests and obtain all consents required for Customer Data to be processed as contemplated by the Agreement. Clients are solely responsible for the accuracy, quality and legality of Customer Data.
Details of processing. Subject matter: Customer Data. Duration: until termination of the Agreement. Purpose: provision of the Service and performance of Hanuman IT's obligations. Data subjects: patients, physicians and staff of the client. Categories: identification and contact data, and health/laboratory data, which is sensitive data under Section 26 of the PDPA.
4. Security and Confidentiality
Hanuman IT implements appropriate technical and organizational measures, including access control based on least privilege, encryption in transit, audit logging and backups. Personnel with access to Customer Data are bound by confidentiality obligations. Hanuman IT will notify the client without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data.
5. Rights of Data Subjects and Requests
The Service provides functions that clients may use to retrieve, correct, delete or restrict Customer Data. Where clients cannot do so themselves, Hanuman IT will provide reasonable cooperation, at the client's cost where legally permissible. If a Request is made directly to Hanuman IT, Hanuman IT will not respond without the client's prior authorization unless legally compelled, and will promptly forward the Request to the client.
Hanuman IT does not disclose or sell Customer Data to third parties.
Government requests. Hanuman IT will attempt to redirect law enforcement demands for Customer Data to the client. If compelled to disclose, Hanuman IT will give the client reasonable notice unless legally prohibited.
Data protection contact: contact@hanumanit.co.th
6. Sub-processors
Clients agree that Hanuman IT may engage sub-processors (for example, hosting, backup or communication providers) only to the extent needed to deliver the Service. Customer Data is never used for promotional purposes. The current list of sub-processors for each client is set out in the Agreement or provided on request to contact@hanumanit.co.th. Hanuman IT will notify clients at least 14 days before adding or replacing a sub-processor, and clients may object within that period.
7. Return and Deletion of Data
Upon termination of the Agreement, Hanuman IT will, at the client's choice, return or delete Customer Data within a reasonable period, unless retention is required by law.
8. Relationship with the Agreement
Except as amended by this Addendum, the Agreement remains in full force. If there is any conflict, this Addendum prevails. Claims under this Addendum are subject to the limitation of liability in the Agreement. No third party may enforce this Addendum. This Addendum is governed by the governing law of the Agreement, unless otherwise required by Data Protection Laws.
9. Legal Effect and Updates
This Addendum becomes legally binding between the client and Hanuman IT when signed by both parties. Hanuman IT will review and update this Addendum at least annually. To execute this Addendum, please contact contact@hanumanit.co.th.