Data Processing Agreement
Effective date: August 25, 2026 · Between CCM Bridge Inc. (“Processor”) and the customer organization identified in the applicable order form or subscription (“Controller”)
1. Subject Matter and Duration
This Data Processing Agreement (“DPA”) governs CCM Bridge Inc.’s processing of Customer Data on behalf of Controller in connection with the RemediTag Service, for the duration of the underlying subscription agreement between the parties.
2. Nature and Purpose of Processing
CCM Bridge processes documents uploaded by Controller (“Customer Data”) solely to perform PDF/UA-1 accessibility validation and remediation, and to generate compliance certificates and related outputs, as instructed by Controller through use of the Service.
3. Scope of Data: Plan-Level Only
The parties acknowledge that Customer Data processed under this DPA consists of plan-level regulatory and template documents (e.g., ANOC, EOC, Summary of Benefits, Formulary, EOB, NOA/NDN materials) and does not include individual member or beneficiary protected health information (PHI). Controller agrees not to submit documents containing member-level PHI through the Service. This DPA is not a HIPAA Business Associate Agreement and does not create business associate obligations.
4. Processor Obligations
CCM Bridge will: (a) process Customer Data only on Controller’s documented instructions, as reflected in the subscription agreement and Controller’s use of the Service; (b) ensure personnel with access are subject to confidentiality obligations; (c) implement appropriate technical and organizational security measures; (d) assist Controller with reasonable requests related to Controller’s own compliance obligations, to the extent consistent with the nature of processing; and (e) delete or return Customer Data upon termination, as described in Section 7.
5. Subprocessors
Controller authorizes CCM Bridge’s use of the following subprocessors: Stripe (payment processing) and its cloud hosting provider (infrastructure hosting). CCM Bridge will provide reasonable notice before adding a new subprocessor materially affecting the processing of Customer Data.
6. Security Measures
CCM Bridge maintains technical and organizational measures appropriate to the nature of Customer Data described in Section 3, including encryption in transit, access controls, and logging. In the event of a security incident affecting Customer Data, CCM Bridge will notify Controller without undue delay after becoming aware of it.
7. Deletion or Return on Termination
Upon termination of the subscription, CCM Bridge will, at Controller’s election, delete or return Customer Data within a reasonable period, except as retention is required by law or for legitimate business recordkeeping (e.g., audit trail of past compliance certificates).
8. Audit
Upon reasonable request and no more than once annually (absent a security incident), CCM Bridge will provide Controller with reasonably available information to demonstrate compliance with this DPA.
9. International Transfers
Not applicable: Customer Data is processed and hosted within the United States.
10. Governing Law
This DPA is governed by the laws of the State of Minnesota, consistent with the governing law of the underlying Terms of Service.
Under review. This document is currently under review by our legal team and may be updated before it is considered final.