Legal
Halingo data processing agreement
Annex 1 to the Halingo terms and conditions. Version 1.0. In force from 27 September 2026.
This is a shortened English version. The agreement is concluded in Dutch or in French, at the customer’s choice. The full Dutch text is the binding version and prevails in the event of any difference with this page. This page exists so that you can read the substance in English before you accept it in Dutch or French.
This agreement is concluded between you, the speech therapy practice that registers on Halingo and acts as controller, and Autopilot Pte. Ltd., 160 Robinson Road, #14-04 Singapore Business Federation Centre, Singapore 068914, Singapore, UEN 202011848W, acting as processor. You accept it at registration. It forms part of your contract and applies from the first day of your trial. It satisfies Article 28(3) of Regulation (EU) 2016/679.
1. What it covers
You enter personal data about your patients and the people around them in Halingo. For that data you are the controller and we are the processor. Annex I describes the processing, Annex II the security measures and Annex III our sub-processors. For data about you as our customer we are ourselves the controller, and our privacy statement governs that. This agreement lasts for as long as we process personal data for you, which is for the term of your contract and afterwards for as long as we hold your data in the read-only version under section 11.
2. Only on your instructions
We process the personal data only on your documented instructions, including as regards transfers to a third country. Your instructions are this agreement, the features of Halingo as described in our help centre, and any further written instruction you send to support@halingo.be. We do not process the data for our own purposes and make no copy of it beyond a backup or what performing this agreement requires. If we consider an instruction to breach the Regulation or Belgian data protection law we tell you without delay and may suspend it until you confirm or amend it. We do not open the content of a patient file except at your express request or instruction, for example to investigate a problem you reported, or where a binding legal obligation requires it. Every such access is logged and the log is available to you on request.
3. Support
Our support is a processing activity under this agreement and is described in Annex I. We ask you not to send patient data with a support question. If a ticket, a description or an attachment contains patient data anyway, we use it only to answer your question and we act as your processor there too. We delete the file as soon as your question is resolved and within seven calendar days at the latest, we record the deletion in the ticket, and we share it with nobody outside the support team. Attachments are deleted at the latest six months after the ticket closes and tickets at the latest twenty-four months after it closes. If it is a large file, a complete patient record or a collective statement, we assess the same day whether there is a personal data breach and inform you under section 8.
4. Confidentiality of the people with access
Access is given only to people who need the data for their task, and only to what they need for it. Each of them is bound by a written confidentiality undertaking with the same content and the same duration as your own professional secrecy, surviving the end of their engagement. We claim no professional secrecy of our own, and your duty under Article 458 of the Criminal Code remains yours. Under Article 9 of the Act of 30 July 2018 we designate the categories of persons with access to health data, with a precise description of their capacity, and we keep that list current and available to the Data Protection Authority and, on request, to you.
5. Security
We take the technical and organisational measures required by Article 32 of the Regulation. They are described in Annex II. We may change them provided the level of security does not fall, and Annex II is then updated.
6. Sub-processors
You give us general written authorisation to engage sub-processors. The current list is in Annex III. We notify you by email at least thirty calendar days before adding or replacing one. You may object in writing within those thirty days on a reasoned ground related to data protection. If we find no solution together within thirty days, you may terminate your contract free of charge, keeping all your rights under section 11. We impose the same obligations on every sub-processor by contract and remain fully liable to you for their compliance.
7. Helping you with data subject rights
We help you handle requests from your patients and other data subjects, and we give you the data and the technical means you need within five working days. If a data subject writes to us directly we do not answer ourselves: we refer them to you and inform you without delay.
8. Personal data breaches
We notify you of any personal data breach without undue delay and in any event within twenty-four hours of becoming aware of it, by email and, if you gave us a telephone number, by telephone as well. The notification states the nature of the breach, the categories and estimated number of data subjects and records, the likely consequences, the measures taken and proposed, and our contact person. If not everything is known we tell you what we know and complete it as we learn more. We do not notify the supervisory authority and do not communicate with data subjects ourselves unless you instruct us in writing to do so, and we give you everything you need to meet Articles 33 and 34 in time.
9. Helping you with Articles 32 to 36
We help you comply with Articles 32 to 36 of the Regulation, in particular with a data protection impact assessment and with a prior consultation of the supervisory authority, and we make the necessary information available within ten working days, including the description of the measures in Annex II.
10. Information and audits
We make available all information needed to demonstrate compliance with this agreement. We allow audits and inspections by you or by an auditor you appoint who is not a competitor of ours, announced in writing at least thirty calendar days ahead, or five working days ahead after a personal data breach or at the request of a supervisory authority. An audit takes place at most once per calendar year, during office hours, and disturbs the service as little as possible. We may produce a recent independent audit report or a valid certification instead; if that does not answer your questions you keep your right to an on-site audit. Each party bears its own costs, unless the audit reveals a serious failure on our side, in which case we bear your reasonable costs.
11. What happens to the data at the end
We say it as it is: Halingo has no export function today. You cannot extract your data set in one operation. You can show your agenda on another device through a link, and you can open, print or save as a pdf each patient file, report, invoice, certificate and collective statement individually.
That is why we do not delete your data when your contract ends. You keep free access, with your existing credentials, to a read-only version of your own data in Halingo: you can consult, open and print everything, and you can no longer add or change anything. That is an obligation on our side and not a courtesy, and we maintain the read-only version for as long as we offer Halingo.
The choice between keeping, returning and erasing is yours, as Article 28(3)(g) requires. If you do nothing we keep the data as described above, because as a healthcare provider you must be able to keep consulting your patient records. If you ask us to erase your data we first make it available to you in a readable form, free of charge and within thirty calendar days, and we erase nothing before we have done so. Then we erase all personal data, including from the backups, except what we must keep by law, and we confirm the erasure in writing. If we ever discontinue Halingo we give you at least six months’ notice and make your data available in a readable form before anything is deleted. This agreement continues to apply for as long as we still hold the data.
You remain responsible, as a healthcare provider, for keeping your patient records for at least thirty years from the last patient contact, under Articles 33 to 35 of the Act of 22 April 2019. A read-only version on our systems is not legal retention and does not discharge that duty.
12. Transfers outside the European Economic Area
The personal data is stored with the sub-processors in Annex III, in the European Union only. We keep no copies outside the European Economic Area. Our staff in Singapore have access to that data to run, support and secure Halingo, and that access is a transfer under Chapter V of the Regulation.
That transfer takes place under the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, module two, controller to processor. By accepting this agreement you conclude those clauses with us: you act as data exporter and we as data importer. Annexes I, II and III to this agreement serve as Annexes I, II and III to the clauses. The full text of the clauses is available on request at support@halingo.be. Where the clauses and this agreement conflict, the clauses prevail. We have assessed the risks of the transfer and provide that assessment on request. If an authority outside the European Economic Area asks or orders us to hand over your personal data, we tell you without delay, challenge the request with every available remedy, and hand over no more than is strictly necessary. If we are legally barred from telling you, we work to have that bar lifted and tell you as soon as we may.
13. The national register number
We process the social security identification number (the NISS or national register number) only as processor, on your instructions and within the authorisation you hold as a healthcare provider. We do not use it for our own purposes, not as a search key or identifier in our own systems, and we do not process it in the support channel.
14. Liability and order of precedence
Each party is liable under Article 82 of the Regulation. The cap in section 10 of the terms and conditions does not apply to liability towards data subjects under that Article 82. Where documents conflict, this is the order: first the standard contractual clauses referred to in section 12, then this agreement, then the terms and conditions.
Annex I. Description of the processing
Parties. Controller: the customer, a speech therapy practice established in Belgium. Processor: Autopilot Pte. Ltd., Singapore.
Subject matter. Making Halingo available, a web application for running a speech therapy practice, and the support that goes with it.
Nature and purpose. Storing, consulting, altering, structuring, displaying, printing and sending the data the customer enters, as far as the features of Halingo involve it: the patient file, the agenda, treatment plans and reports, invoicing, certificates for care provided, third-payer collective statements, and the email the customer sends to a patient from Halingo. In addition: answering support questions, making backups, securing the service and investigating reported problems.
Categories of data subjects. Patients of the customer; their legal representatives, contact persons and persons of trust; their prescribing doctors and other healthcare providers; their schools, teachers and care coordinators; and the customer and their users, in so far as their data appears in a patient file.
Categories of personal data. Identity: first name and surname, photo, file status, free tags. Administrative: NISS number, health insurance fund, CG1 or CG2 code, third-payer arrangement. Environment: contact person, school and teacher, care coordinator, prescribing doctor. Financial: invoices, certificates and their numbers, nomenclature codes, collective statements, administrative fees, the email address of the patient or their representative. Communication: the per-patient email log with the status, type, recipient address and time.
Special categories (Article 9). Health data: the speech therapy problem, the reimbursement type, the initial and follow-up assessments, the treatment plan and its goals, reports and uploaded documents including the doctor’s prescription, the number and course of the sessions, and the nomenclature codes that point to a pathology.
Safeguards for those special categories. The measures in Annex II, the confidentiality undertaking in section 4, the list referred to in section 4, and the logging of every access to a patient file.
Frequency. Continuous, for as long as the customer uses Halingo, and afterwards in the read-only version under section 11.
Duration. The term of the customer’s contract, and afterwards for as long as the data is kept under section 11.
Support as a separate processing activity. Autopilot processes personal data the customer communicates in a support ticket or in an email to support@halingo.be, attachments included, only to answer the customer’s question. Section 3 governs that processing, including deletion within seven calendar days, attachments after six months and tickets after twenty-four months.
Transfer to third parties on the customer’s instruction. If the customer switches on the connection with the Rosa appointment platform, Halingo and Rosa exchange appointment data in both directions. The customer signs in to Rosa themselves and makes the connection with a token from their own Rosa profile. That exchange takes place on the customer’s instruction and under the contract the customer concluded with Rosa ASBL.
Annex II. Technical and organisational measures
These are the measures in force today.
Encryption in transit. All connections to app.halingo.be, our website and the help centre run over TLS. The help centre also sends an HSTS header valid for one year, subdomains included.
Access management. Access only for people who need the data for their task, with a personal account and a personal password. Inside the practice the customer decides who has access to which file; a practice administrator has access to every file of that practice. A file cannot be shared with a therapist of another practice.
Confidentiality. A written confidentiality undertaking for everyone who works for Autopilot, with the same content and duration as the customer’s professional secrecy, surviving the end of their engagement. The list of categories of persons with access to health data referred to in section 4.
Logging. Every access by Autopilot to the content of a patient file is logged and available to the customer on request. The application logs sign-ins and actions for security and troubleshooting.
Security of the public forms. The contact form and the ticket form are protected by Google’s reCAPTCHA spam protection, which loads only once the visitor starts filling the form in, and by a hidden field against automated submissions. Ticket attachments are checked for type and size.
Limiting data in the support channel. The warning on the form, the instruction to support staff to delete an attachment containing patient data within seven calendar days and to record the deletion in the ticket, and the scheduled job that deletes attachments after six months and tickets after twenty-four months.
Hosting in the European Union. The application and the data the customer enters sit with Scaleway SAS in France. The website and the help centre sit with Odoo SA in the European Union. No local copies are kept on any device outside the European Economic Area.
Backups. Backups of the data are made and kept in the European Union, with the sub-processors in Annex III.
Review. This annex is reviewed at least once a year, and whenever a sub-processor, a retention period or a feature of the application changes.
Annex III. Sub-processors
| Sub-processor | Task | Place of processing |
|---|---|---|
| Scaleway SAS, 8 rue de la Ville l’Évêque, 75008 Paris, France | Hosting the web application app.halingo.be, everything the customer enters in it, and the backups | France |
| Odoo SA, Chaussée de Namur 40, 1367 Grand-Rosière, Belgium | Hosting the website, the help centre, the tickets and the attachments | European Union |
| Twilio Ireland Limited (SendGrid), Dublin, Ireland | Sending the email Halingo sends, including the invoices and documents the customer sends to a patient, and the replies to a ticket | European Union, with possible transfer to the United States under the adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework and, where that does not apply, under the standard contractual clauses |
| Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Email traffic to and from support@halingo.be through Google Workspace, in so far as a ticket or an email contains patient data | European Union, with possible transfer to the United States on the same grounds |
| Stripe Payments Europe, Limited, 25/28 North Wall Quay, Dublin 1, Ireland | Processing the payment of the customer’s subscription. Stripe receives no patient data | European Union |
Rosa ASBL is not a sub-processor of Autopilot. If the customer switches on the connection with Rosa, Rosa acts under the contract the customer concluded with Rosa.
The current version of this list is on this page. Changes are announced under section 6.
Related documents. Terms and conditions · Privacy statement · Cookie policy