Data processing

Last updated: February 2025

This Data Processing Agreement (“Agreement”) describes how 3AE Health Ltd (“3AHealth”) processes personal data in connection with the Website and related services.

Important:
3AHealth does not process or store customer or user personal data through the Website, except for minimal analytics and security logs.

This DPA is provided for transparency and to comply with modern EU GDPR expectations.


1. Roles of the Parties

  • Controller: The Website visitor

  • Processor: 3AHealth

However, since no user-provided data is collected, processing activities are extremely limited.


2. Categories of Data Processed

We only process:

  • Technical logs (IP address, browser type)

  • Cookie preferences

  • Basic analytics data (aggregate, anonymous)

We do not process:

  • personal identifiable information

  • customer datasets

  • health data (special category)

  • uploaded content

  • user accounts

  • tracking beyond analytics


3. Purpose of Processing

We process minimal data solely to:

  • maintain Website functionality

  • monitor Website performance

  • protect against spam and security threats

3AHealth does not use this data for advertising, profiling, or cross-site tracking.


4. Data Storage & Retention

  • Logs are retained only as long as necessary for security.

  • Analytics data is anonymized.

  • No persistent personal data is stored.


5. Subprocessors

We may use:

  • hosting providers

  • analytics tools

  • CDN or caching providers

All subprocessors comply with GDPR and modern EU data protection standards.

A full list is available upon request.


6. Security Measures

3AHealth uses industry-standard security controls, including:

  • encrypted communications (HTTPS)

  • firewall and denial-of-service protection

  • infrastructure hardening

  • regular vulnerability management


7. International Transfers

Data may be processed within the EU or EEA.
If transferred internationally, it is safeguarded under:

  • Standard Contractual Clauses (SCCs), or

  • adequacy decisions


8. Data Subject Rights

Visitors may request:

  • access

  • correction

  • deletion

  • restriction

  • portability

of any personal data that may exist (typically none).


9. Contact

For GDPR inquiries:
📧 info@3ahealth.com