Start free

Health Data Addendum

Extra rules for clinic, health and telehealth sites, and for any special-category data.

Plain-English baseline. This is a clear, good-faith starting draft — not legal advice. Have your counsel review and adapt it before relying on it for your jurisdiction.
Last updated 2026

1. When this addendum applies

It applies to any site built on xigzag that uses a clinic, health, hospital or telehealth template, or that collects special-category data (GDPR Art. 9; "sensitive information" under PIPEDA and Law 25): health, medical history, symptoms, medication, diagnoses, disability, genetic or biometric data, racial or ethnic origin, religion, sexual life or orientation, political opinions or trade-union membership. It adds to the DPA and the Terms. The site owner must accept it before the site can be published.

2. Your responsibilities as the site owner

  • You are the controller. You need a lawful condition for health data (for example explicit consent, Art. 9(2)(a), or provision of health care by a professional under a duty of secrecy, Art. 9(2)(h)) and any licence your profession requires.
  • Collect only what you need, tell patients why in your own privacy notice, and get express consent where your law requires it (PIPEDA and Law 25 treat health data as sensitive).
  • Do not use the site for emergencies, and say so on the site.
  • Carry out a data-protection impact assessment (Art. 35 GDPR; Law 25 privacy impact assessment) where required.

3. What the platform does

  • Encryption at rest: every field we recognise as special-category (and every field you mark sensitive) is sealed with AES-256-GCM before it is stored, on forms, orders and cases.
  • Kept out of side channels: these fields are never put into analytics, never copied into notification or confirmation emails (the email links to the Studio instead), never sent to connectors or webhooks, and never included in AI prompts.
  • Access: only people you give access to in the Studio can open them; staff support sessions are logged.
  • Breaches: handled as the DPA section 8 says.

4. No HIPAA Business Associate Agreement

xigzag does not offer a HIPAA Business Associate Agreement (BAA) and makes no claim of HIPAA compliance. If you are a US covered entity or business associate, do not use xigzag to create, receive, keep or send protected health information (PHI).

5. Acceptance

You accept this addendum in the Studio before a health site is published. We record who accepted, when and which version (1.0).

Questions?

We're happy to talk it through.

Email hello@xigzag.com →