Data Processing Addendum
Last updated: Aug 2026
1. Roles of the Parties
1.1 In connection with the Services, we are processing Personal Data on your behalf.
1.2 Each Party agrees to comply with the Data Protection Law in the Processing of Transferred Data.
2. Processing of Personal Data
2.1 You instruct us to process Transferred Data in accordance with this Data Processing Addendum (including in accordance with Attachment A).
2.2 We agree not to process Transferred Data other than on your documented instructions.
3. Security
3.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we agree to implement appropriate technical and organisational measures in relation to the Transferred Data to ensure a level of security appropriate to that risk in accordance with the Data Protection Law.
3.2 In assessing the appropriate level of security, we agree to take into account the risks that are presented by Processing, in particular from a Personal Data Breach.
4. Sub-Processing
4.1 You authorise our engagement of the Sub-Processors already engaged by us at the Commencement Date, which are set out in Attachment B.
4.2 Where we wish to engage a new Sub-Processor, we agree to provide written notice to you of the details of the engagement of the Sub-Processor at least 14 days' prior to engaging the new Sub-Processor (including details of the processing it will perform). You may object in writing to our appointment of a new Sub-Processor within 7 days of such notice, provided that such objection is based on reasonable grounds relating to data protection. In such event, the Parties will discuss such concerns in good faith with a view to achieving resolution. If the Parties are not able to achieve resolution, we may, at our election:
- (a) not appoint the proposed Sub-Processor;
- (b) not disclose any Transferred Data we process on your behalf to the proposed Sub-Processor; or
- (c) terminate the Services (and the Terms) for convenience, in which case, clause 10.6 of the Terms will apply.
4.3 You agree that the remedies described above are the only outcomes available if you object to our engagement of any proposed Sub-Processor.
4.4 Where we engage a Sub-Processor to process Transferred Data, we agree to enter into a written agreement with the Sub-Processor containing data protection obligations no less protective that those in this Data Processing Addendum with respect to the Transferred Data, and to remain responsible to you for the performance of such Sub-Processor's data protection obligations under such terms.
4.5 Where the transfer of Transferred Data from us to a Sub-Processor is a Restricted Transfer, it will be subject to an appropriate UK Transfer Mechanism (and the accompanying necessary documents or legislation referred to within it), which shall apply in addition to this Data Processing Addendum, and the UK Transfer Mechanism is considered an appropriate safeguard.
5. Data Subject Rights
5.1 Taking into account the nature of the Processing, we agree to assist you by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of your obligations, as reasonably understood by you, to respond to requests from Data Subject to exercise their rights under the Data Protection Law.
5.2 We agree to:
- (a) promptly notify you if we receive a request from a Data Subject under the Data Protection Law in respect of Transferred Data; and
- (b) ensure that we do not respond to that request except on your documented instructions or as required by the Data Protection Law, in which case we shall, to the extent permitted by the Data Protection Law, inform you of that legal requirement before we (or our Sub-Processor) respond to the request.
6. Personal Data Breach
6.1 We agree to notify you without undue delay upon becoming aware of a Personal Data Breach affecting Transferred Data, and to provide you with sufficient information to allow you to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Law.
6.2 We agree to co-operate with you and take reasonable commercial steps as directed by you to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
6.3 If you decide to notify a Supervisory Authority, Data Subjects or the public of a Personal Data Breach, you agree to provide us with advance copies of the proposed notices and, subject to the Data Protection Law (including any mandated deadlines under it), allow us an opportunity to provide any clarifications or corrections to those notices.
7. Data Protection Impact Assessment and Prior Consultation
7.1 We agree to provide reasonable assistance to you, at your cost (to be charged on a reasonable time and materials basis), with any data protection impact assessments, and prior consultations with Supervisory Authorities or other competent data privacy authorities, which you reasonably consider to be required by the Data Protection Law or any other data protection laws.
8. Deletion or Return of Personal Data
8.1 Subject to any document retention requirements at law, we agree to promptly and in any event within 30 business days of the date of cessation of any Services involving the Processing of Transferred Data, delete and procure the deletion of all copies of those Transferred Data.
9. Audit Rights
9.1 Subject to this clause 9, where required by the Data Protection Law, we shall make available to you on request all information reasonably necessary to demonstrate compliance with this Data Processing Addendum, and shall allow for and contribute to audits, including inspections, by you or an auditor mandated by you in relation to the Processing of Transferred Personal Data by us.
9.2 Where clause 9.1 applies, any audit (or inspection):
- (a) must be conducted during our regular business hours, with reasonable advance notice (which shall not be less than 30 business days);
- (b) will be subject to our reasonable confidentiality procedures;
- (c) must be limited in scope to matters specific to you and agreed in advance with us;
- (d) must not require us to disclose to you any information that could cause us to breach any of our obligations under the Data Protection Law;
- (e) to the extent we need to expend time to assist you with the audit (or inspection), this will be funded by you, in accordance with pre-agreed rates; and
- (f) may only be requested by you a maximum of one time per year, except where required by a competent Supervisory Authority or where there has been a Personal Data Breach in relation to Transferred Personal Data, caused by us.
10. Definitions
10.1 In this Data Processing Addendum, capitalised terms have the meaning given to them in the main body of the Terms, and as follows:
Data Protection Law means the United Kingdom Data Protection Act 2018 and the EU GDPR as incorporated into United Kingdom law by virtue of Section 3 of the United Kingdom's European Union (Withdrawal) Act 2018.
Restricted Transfer means a transfer of Personal Data from the United Kingdom to any other country which is not subject to adequacy regulations pursuant to the Data Protection Law.
Transferred Data means any Personal Data that is Processed by us on your behalf in connection with the Services.
UK Transfer Mechanism means the legal methods and safeguards permitted under the Data Protection Law for dealing with Restricted Transfers, including adequacy decisions, standard contractual clauses, binding corporate rules, and other appropriate safeguards as recognised under the Data Protection Law.
10.2 The terms, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” (including “Processed”) and “Sub-Processor” shall have the same meaning as in the Data Protection Law.
Attachment A - Description of Transfer
Categories and Treatment of Personal Data
| Personal Data Transferred | Basic identifying information:
Employment information:
Financial information:
Lifestyle and preferences:
Professional information:
Audio-visual data:
Educational information:
Family information:
Identification information:
Online identifiers:
Social media data:
Customer interaction data:
Other: ________________________________________________________ |
|---|---|
| Special Categories of Personal Data and Criminal Convictions and Offences |
|
| Relevant Data Subjects |
|
| Frequency of the Transfer | Continuous. |
| Nature of the Transfer | To provide the Services or as required by Law. |
| Purpose of the Processing | In connection with the provision of the Services. |
| Duration of the Processing | The term of the Services and for a period of 30 days after the time the Services have stopped being supplied. |
Attachment B - List of Sub-Processors
List of Sub-Processors
| Sub-Processor Name | Location | Purpose/Services | Website & Contact Details |
|---|---|---|---|
| Amazon Web Services, Inc. (and affiliates) | UK: eu-west-2 (London) | Application hosting, authentication (Amazon Cognito), primary database (Amazon RDS for PostgreSQL), file storage for medication/EMIS uploads (Amazon S3, optional AWS KMS encryption), transactional email (Amazon SES). Processes account, usage, billing-related and practice-uploaded data, depending on the features used by the customer. | |
| Stripe Payments Europe, Ltd. / Stripe, Inc. (as applicable to your Stripe account) | Ireland and United States (depending on Stripe's processing infrastructure and applicable contracting entity) | Processes customer billing information, payer name, email address, subscription metadata, payment method details, fraud-prevention signals and transaction records. Payment card data is collected and stored directly by Stripe; the Company does not store full payment card numbers (PANs). | |
| Sentry, Inc | Germany (EU) - data ingested via ingest.de.sentry.io | Application error monitoring, diagnostics and performance tracing. May process IP addresses, device/browser information, request metadata and application error logs. Browser-side telemetry is enabled only where the user has provided the required consent in accordance with the Cookie Policy. | |
| Umami Software, Inc. (Umami Cloud) | EU Cloud region as per Umami Cloud settings | Privacy-oriented website analytics for public and marketing pages only (page views, referrer, browser/OS/device type, country). Does not set browser cookies. Browser-side collection is enabled only where the visitor has provided analytical/performance consent. | |
| Arcjet, Inc. | United Kingdom and European Union | Rate limiting, bot detection, and request shielding on API routes. Processes IP addresses, request metadata and security-related telemetry for rate limiting, bot detection, abuse prevention and API protection. |