HDS - Representation of Guarantees

HDS - Representation of Guarantees

Hébergeurs de Données de Santé: 
Representation of Guarantees

September 2025

Background: The purpose of the table below is to provide customers of Zoho Creator with greater transparency regarding the scope of the service covered by HDS certification. It enables customers to know about the various players on which Zoho Creator relies on to deliver its service. 

Thus, this standard representation is used to list the players involved in the processing of DSCPs (Données de Santé à Caractère Personnel (Personal health data)) in the context of the proposed hosting service. 

Business name of the actor

Role in the hosting service (Host/ processor of the host)

HDS certified (Yes/ No/ Exempted)

SecNumCloud 3.2 qualified

Hosting activities in which the player is involved

Access to personal health data from countries outside the European Economic Area, by the Host or one of its processors

Host or processor subject to a risk of access to personal health data from outside the European Economic Area, imposed by the legislation of a third country in breach of EU law

Zoho Creator

     Host

     Processor

     Yes

     No

     Exempted

     Yes, no risk of unauthorized access to data covered by HDS framework requirement 30

     No

Activities 2 to 5, please refer to external page published by ANS

 

     Yes

     No, no access to data from a country outside the European Economic Area

If yes, specify the country concerned:
INDIA
1. Transfer of Personal Health Data from EEA to India is not covered by adequacy decision within the meaning of Article 45 of GDPR.

2. To govern this transfer, implemented and documented appropriate safeguards such as Standard Contractual Clauses within the meaning of Article 46 of GDPR.

     Yes

     No

If yes, specify the country concerned: INDIA

Transfer impact assessment conducted in accordance with Article 46 of GDPR shall be shared upon request as specified in the contract

Colocation Provider (Details can be provided upon request)

     Host

     Yes

     No

     Exempted

     Yes, no risk of unauthorized access to data covered by HDS framework requirement 30

     No

1. The provision and maintenance in operational condition of physical sites enabling the hosting of the hardware infrastructure of the information system used for processing health data;

     Yes

     No, no access to data from a country outside the European Economic Area

     Yes

     No

Sub-processor (Google Cloud Translation)

     Host

     Processor

     Yes

     No

     Exempted

     Yes, no risk of unauthorized access to data covered by HDS framework requirement 30

     No

Activities 1 to 5, please refer to HDS external page for more information

     Yes

     No


Details of sub-processors, the types of data they process, and their processing locations are listed on the sub-processors page

     Yes

     No