<!--
  ┌────────────────────────────────────────────────────────────────────────┐
  │  FICTIONAL TEACHING DOCUMENT — "Claude for Legal: A Guided Tour"          │
  │  A synthetic Data Processing Agreement, invented for practice. Here       │
  │  Sablefield is the PROCESSOR and Tellermark Health is the CONTROLLER.     │
  │  Written with planted, documented issues so a DPA-review skill (processor │
  │  side) has something to find:                                            │
  │    §5  breach notice in 24 hours (tighter than Sablefield can meet)      │
  │    §6  per-subprocessor prior written consent / veto (not notice-object) │
  │    §3  PHI flows but NO BAA / no HIPAA flow-down (sectoral defect)        │
  │    §9  data-breach liability carved OUT of the cap — uncapped            │
  │  Not legal advice; not a model DPA. Free to reuse for learning.          │
  └────────────────────────────────────────────────────────────────────────┘
-->

# Data Processing Agreement

**Between Tellermark Health, Inc. (“Controller”) and Sablefield Robotics, Inc. (“Processor”)**

> This Data Processing Agreement governs Processor's handling of personal data on Controller's behalf in
> connection with the GripSense robotic systems deployed at Controller's fulfillment and remote-monitoring
> sites. It forms part of the Master Services Agreement between the parties.

## 1. Roles

Controller determines the purposes and means of processing. Processor processes personal data only on
Controller's documented instructions, including the personal data of Controller's warehouse and clinical
personnel captured through device telemetry, app usage, and on-site cameras.

## 2. Scope of data

The personal data processed includes worker identifiers, location and movement telemetry, device and app
usage logs, and operational records generated at Controller's sites. Controller's sites include
remote-monitoring clinics at which **patient-associated information may be present in the operating
environment.**

## 3. Compliance

Each party shall comply with applicable data protection laws. **This Agreement constitutes the parties'
complete understanding regarding data protection, and no separate business associate agreement or
health-data addendum is required.** Processor shall process data in accordance with this Agreement.

## 4. Security

Processor shall maintain administrative, technical, and physical safeguards appropriate to the data.

## 5. Breach notification

Processor shall notify Controller of any actual or suspected personal-data breach affecting Controller's
data **within twenty-four (24) hours** of Processor becoming aware of it, and shall provide a full root-cause
analysis within seventy-two (72) hours.

## 6. Subprocessors

Processor shall not engage any subprocessor to process Controller's data without **Controller's prior written
consent for each such subprocessor.** Controller may withhold consent in its sole discretion. Processor
remains liable for the acts and omissions of any approved subprocessor.

## 7. Data subject requests

Processor shall, within five (5) business days, forward to Controller any request it receives from a data
subject relating to Controller's data, and shall not respond to the data subject directly except to confirm
receipt and to direct the data subject to Controller.

## 8. Deletion

Upon termination, Processor shall delete or return all of Controller's data at Controller's election.

## 9. Liability

Each party's aggregate liability under the MSA is capped at fees paid in the prior twelve (12) months.
**The foregoing cap shall not apply to, and Processor's liability shall be unlimited for, any claim arising
out of a personal-data breach or Processor's handling of Controller's data.**

## 10. Governing law

This Agreement is governed by the laws of the State of Delaware.
