9 days ago
Hi,
I’m developing a web application for beauty salons in Japan. End users may submit health-related information such as medication use, allergies, or medical history through a pre-consultation form.
The data itself is stored in Supabase, but it may pass through and be processed by the application hosted on Railway.
I noticed that Railway’s DPA, Exhibit A, states:
“Sensitive Data or Special Categories of Data: None.” Railway_Corporation_Data_Proces…
Does this mean that health-related personal data must not be processed through an application hosted on Railway under the standard DPA?
If it is permitted, could you please clarify how this should be interpreted?
Thank you.
1 Replies
9 days ago
Our published Data Processing Addendum is the only data-processing agreement we offer. We don't amend it for any customer or plan. Exhibit A lists no sensitive or special-category data, so the DPA has no contractual terms for intentionally processing health data. We can't tell you what you may lawfully process. That depends on your obligations under Japanese law and any other rules that apply to you, so it's best decided with your own counsel. Related material is published on our legal page, in the subprocessor list, and on trust.railway.com, which includes our SOC 2 Type II report.
If your processing falls under HIPAA, a Business Associate Agreement is available on the Enterprise plan. It requires a $1,000/month minimum, committed for 12 months, and it sits alongside the DPA rather than changing it.
Status changed to Awaiting User Response Railway • 9 days ago
2 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 2 days ago