Data Processing Agreement

Data Processing Agreement

How we process personal data on your behalf when you use our services, to the extent we act as your processor.

Last updated:  14 September 2026

 

This Data Processing Agreement forms part of your contract with us, alongside our General Terms and Product-Specific Terms. Where there’s a conflict between this DPA and any other part of your contract on anything to do with data protection, this DPA takes priority — see our General Terms. It doesn’t apply to the extent we act as controller rather than processor — see the clause about ‘Roles’ and our Privacy Policy for when that’s the case. References to "we," "us" and "Agilio" in this DPA mean the Agilio Group company you’re contracting with for the relevant product — see your order form or sign-up confirmation for which entity that is. Which entity you’re contracting with, and whether it’s acting as controller or processor for a given set of personal data, can both depend on the specific product and how you’ve subscribed to it.

1. Roles

1.1 Where you’re subscribing on behalf of an organisation — a practice, group or other business — you’re the data controller of any personal data processed through the services (for example, data about your staff, patients or clients), and we’re the data processor, processing it on your documented instructions. Where you’re subscribing as an individual, sole trader or practitioner in your own capacity — with no organisation standing between you and us — we’re the data controller of your own personal data, and our Privacy Policy, not this DPA, sets out how we handle it; by entering into this contract in that capacity, you confirm we gave you the opportunity to access and read our Privacy Policy beforehand, and that you’ve done so.

1.2 Where a product lets one of your own administrators grant another of your authorised users visibility of personal data — for example, a practice administrator seeing a team member’s training or CPD completion records — that visibility is part of the service we provide on your documented instructions (as embodied in how you’ve configured or use the service). It doesn’t create a separate arrangement between us and the individual concerned, and you remain the controller of that data throughout.

1.3 If you’re a processor acting on behalf of your own third-party controller, you’re a processor for the purposes of this DPA and we’re your sub-processor, and you must ensure your instructions to us are consistent with that third-party controller’s own instructions to you.

1.4 If we receive a request or instruction from a third party claiming to be the controller of personal data we process on your behalf, we’ll tell them to contact you directly, rather than acting on it.

1.5 Whatever capacity you’re acting in under this clause — controller, or processor for your own third-party controller — you’re responsible for complying with your own obligations under Applicable Data Protection Law in that capacity, including having a lawful basis for any processing you carry out and for any instructions you give us.

1.6 Where you input personal data about someone else through our services — for example, a patient's details — you must have an appropriate lawful basis for doing so, and you should only input the data you actually need for that purpose.

2. What we process, and why

2.1 We process the personal data you or your authorised users upload, store or generate in connection with our services for as long as your contract with us runs, solely to provide the services to you. We don’t use it for any other purpose without your instruction.

2.2 We only process personal data on your documented instructions — including instructions given through your configuration and use of the services — unless we’re required to do otherwise by Applicable Data Protection Law, in which case we’ll tell you before processing (unless the law prohibits this on important public-interest grounds). If we think an instruction you’ve given us doesn’t comply with data protection law, we’ll tell you.

2.3 The subject matter, categories of data subjects and personal data, and other details of this processing are set out in Annex 1 below.

2.4 If you reasonably believe we’re processing personal data otherwise than on your documented instructions or in breach of this DPA, you can tell us to stop that specific processing. We’ll do so promptly while we investigate, without you needing to prove the breach first — this is in addition to, and doesn’t limit, your other rights and remedies under this DPA. Stopping that specific processing doesn’t affect your obligation to keep paying fees in the meantime.

2.5 If we receive a legally binding demand for personal data we process on your behalf from a public authority — including the police, a court, a regulator or a government body — we’ll tell you before disclosing anything in response, unless we’re legally prohibited from doing so, doing so would prejudice a law enforcement investigation, or you’ve already been directly approached. Where we’re restricted from telling you, we’ll challenge the scope of the restriction to the extent we reasonably can, and tell you as soon as the restriction is lifted.

3. Sub-processors

3.1 We use a number of sub-processors — including cloud hosting, infrastructure and AI providers — to deliver our services. You generally authorise us to engage these, including any sub-processor currently listed on our Sub-Processors page, and any new or replacement sub-processor we publish there from time to time in line with this clause.

3.2 We’ll publish details of any new or replacement sub-processor on our Sub-Processors page before it starts processing your personal data — you can subscribe there to be notified directly of any change — and you’re treated as having no objection unless you tell us otherwise within 10 days of that publication. If you object on reasonable data protection grounds within that 10-day period, we’ll discuss with you whether we can address your objection — for example, by using a different sub-processor. If we can’t resolve it between us, either of us can end the affected part of your subscription on 30 days’ written notice, without the exit fees or notice periods that would otherwise apply, but without affecting fees already due.

3.3 We remain fully liable to you for a sub-processor’s performance of its data protection obligations, and we impose data protection terms on each sub-processor that are no less protective than this DPA.

4. Security measures

4.1 We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss or damage, proportionate to the harm that could result and the nature of the data involved. A summary of our security measures is set out in Annex 2.D below; details of our current security certifications are available on request through our usual customer support channels. These measures are designed to meet the requirements of Article 32 UK GDPR. We may update these measures from time to time as we consider necessary to reflect evolving industry practice, new technology and emerging threats, provided that doing so doesn’t reduce the overall level of protection.

4.2 Anyone we authorise to process personal data on your behalf is bound by a confidentiality obligation, whether contractual or statutory.

4.3 Your own security responsibilities for your use of our services — including keeping your account credentials secure — are set out in our Acceptable Use Policy.

4.4 You agree that our security measures, taken as a whole, provide a level of security appropriate to the risk to your personal data, having regard to the state of the art, the cost of implementation, and the nature, scope and purposes of the processing.

5. International transfers

5.1 We and our sub-processors may process your personal data in any country where we or they maintain facilities. Where that amounts to a transfer outside the UK or EEA, the safeguards below apply.

5.2 Where we need to transfer personal data outside the UK or EEA — for example, where a sub-processor is based overseas — we put appropriate safeguards in place in line with Applicable Data Protection Law, and carry out a transfer risk assessment where one is required. Where UK law changes how that assessment is carried out (for example, the "data protection test" introduced by the Data (Use and Access) Act 2025, in force from 5 February 2026, in place of the previous adequacy-style test), we apply whatever version of the test is in force at the time.

5.3 Where a transfer of your personal data to us, or by us to a sub-processor, is a restricted transfer under the UK GDPR or EU GDPR (broadly, a transfer to a country not covered by an applicable adequacy decision or regulations), the applicable Standard Contractual Clauses — and, for a transfer from the UK, the International Data Transfer Addendum issued by the UK Information Commissioner that modifies them — are incorporated into, and form part of, this DPA in respect of that transfer, completed with the details in Annex 2 below.

5.4 A transfer of personal data between the UK, the EEA and Switzerland isn't a restricted transfer under Applicable Data Protection Law, since each recognises the others as providing an adequate level of protection. Where personal data governed by the Swiss FADP is transferred to a country not recognised by the Swiss Federal Council as providing an adequate level of protection, we'll put in place the safeguards the Swiss FADP requires for that transfer, which may include the Standard Contractual Clauses referred to above, adapted as Swiss law requires.

6. Helping you meet your own obligations

6.1 Taking into account the nature of the processing, we’ll assist you — by appropriate technical and organisational measures, so far as this is possible — in responding to requests from individuals exercising their data protection rights. We’ll also assist you, taking into account the nature of the processing and the information available to us, in meeting your own obligations around security, breach notification, data protection impact assessments, regulator consultations, and — where you use one of our products to make significant decisions about an individual by automated means — the applicable transparency, human review and contestability safeguards for automated decision-making under Applicable Data Protection Law (Articles 22A to 22D UK GDPR, or Article 22 EU GDPR, as applicable — see the clause about ‘Compliance’ below).

6.2 As standard, and at no extra charge, this assistance includes: the security measures described in the clause about ‘Security measures’ above and Annex 2 below; our compliance documentation and current certifications, available on request through our usual customer support channels; and our breach notification duties under the clause about ‘Breach notification’ below. We may charge our reasonable costs for any further assistance that goes beyond this.

6.3 Where you can fulfil a request from an individual using existing functionality in our services without our help, you should do so directly; our assistance obligation under this clause applies where you can’t.

6.4 If we receive a request directly from an individual that relates to personal data we process on your behalf and identifies you, we’ll tell them to submit their request to you, promptly let you know, and we won’t otherwise respond to that request without your authorisation. You’re responsible for responding to it.

7. Breach notification

7.1 We’ll notify you without undue delay after becoming aware of a security incident affecting your data. So far as we’ve been able to establish at the time of notifying you, our notification will describe: the nature of the security incident, including where possible the categories and approximate number of data subjects and personal data records affected; a point of contact where you can get more information; the likely consequences of the security incident; and the measures we’ve taken, or propose to take, to address it and mitigate its effects. Where we can’t provide all of this information straight away, we’ll provide the rest in phases, without further undue delay, as it becomes available.

7.2 We're not required to review or analyse the content of the personal data affected in order to identify information subject to specific legal requirements, and notifying you of, or responding to, a security incident under this clause isn't an acknowledgement of fault or liability on our part.

8. Audits

8.1 We keep records to demonstrate our compliance with this agreement. On reasonable notice, and no more than once every 12 months (except following a substantiated compliance concern), you or an auditor you mandate can audit our records — including by us making available all information reasonably necessary to demonstrate that compliance — and, where reasonably necessary, our data processing facilities.

8.2 We also keep records of our processing activities as required by Applicable Data Protection Law. Where Applicable Data Protection Law requires us to hold specific information about you or your use of our services for this purpose, you’ll provide it to us and keep it up to date; we may disclose it to a supervisory authority or other regulator if required to do so.

8.3 Where we hold a current independent third-party audit report or certification relevant to your request (such as our Cyber Essentials certificate, available on request through our usual customer support channels), providing you with that report or certification, together with the information in Annex 2.D below, will satisfy a request under this clause without a separate on-site audit — unless your request relates to a substantiated compliance concern that report or certification doesn’t address, in which case the audit right in the paragraph above applies in full.

8.4 We can charge our reasonable costs of an audit under this clause, provided we tell you the basis of any charge in advance. We can object to an auditor you’ve appointed to carry out an audit if, in our reasonable opinion, they’re not suitably qualified or independent, are a competitor of ours, or are otherwise clearly unsuitable — if we object, you’ll need to appoint a different auditor, or carry out the audit yourselves.

9. When your contract ends

When your contract ends, we’ll return or delete personal data at your written direction, or, if you don’t give us a direction, no later than 30 days after your contract ends — matching the data retention terms in our General Terms — unless the law requires us to keep it for longer. We’ll also delete any existing copies we hold, subject to the same exception.

10. Special-category data

Some of our products process special-category data. Where you input special-category data of this kind, you’re responsible for having an appropriate Article 9 condition and, where relevant, an appropriate policy document under the Data Protection Act 2018, and we’ll apply additional access controls appropriate to the sensitivity of that data on top of our standard security measures.

11. Compliance

11.1 Which law governs

We’ll comply with our own obligations relating to the processing of your personal data under this DPA, under whichever of the UK GDPR, the Data Protection Act 2018 and the EU GDPR applies to the processing in question — see the clause about ‘Definitions’ above. Your equivalent obligation, in whichever capacity you act, is set out in the clause about ‘Roles’ above.

11.2 Where EU GDPR applies

The following also apply, in addition to the rest of this DPA, to the extent the EU GDPR applies to the processing of your personal data.

Where we act as processor for personal data of individuals in the EU and we have no establishment in the EU, we’ve appointed Agilio Software Netherlands BidCo B.V. as our representative under Article 27 EU GDPR.

Where you use one of our products to make significant decisions about an individual by automated means, the safeguards described in the clause about ‘Helping you meet your own obligations’ above are the ones Article 22 EU GDPR requires, rather than the different safeguards under Articles 22A to 22D UK GDPR that apply where the UK GDPR governs instead.

The competent supervisory authority for this purpose is set out in Annex 1.E below.

11.3 Where the Swiss FADP applies

The competent supervisory authority for this purpose is the Federal Data Protection and Information Commissioner (FDPIC) — see Annex 1.E below.

12. AI-enabled processing

Where a product you use includes AI-enabled features, we process personal data through those features as your processor on the same basis as the rest of this DPA. We don’t use personal data processed through AI-enabled features to train, fine-tune, or otherwise develop any AI model, and we don’t give it to anyone else for that purpose. Our Product-Specific Terms set out the fuller terms that apply to AI-enabled products, including on data ownership, human oversight, and the underlying AI infrastructure providers we use (also listed on our Sub-Processors page).

13. Definitions

In this DPA:

      • “Applicable Data Protection Law” means whichever of the UK GDPR, the Data Protection Act 2018 (including as amended by the Data (Use and Access) Act 2025), the EU GDPR, the Swiss FADP, and any other data protection law, applies to the processing of the personal data in question, in each case as amended or replaced from time to time.
      • “Controller”, “Processor”, “Data Subject”, “Personal Data” and “Special Category Data” have the meanings given in Applicable Data Protection Law, or, if not defined there, the UK GDPR.
      • “Documented instructions” means the instructions in this DPA, your General Terms, order form and Product-Specific Terms, which are your complete instructions to us for processing your data at the point you enter into this contract. Any further instruction — including one given through your configuration or use of the services — must be consistent with those instructions and capable of being carried out using functionality we ordinarily make available; if you ask us to do something beyond that, we can treat it as a request for additional services under our General Terms rather than an instruction under this DPA.
      • “EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation).
      • “Security incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data we process on your behalf. This meaning applies regardless of which Applicable Data Protection Law governs the data affected.
      • “Sub-processor” means another organisation we engage to process personal data on your behalf in providing the services.
      • “Swiss FADP” means the Swiss Federal Act on Data Protection of 25 September 2020, as revised with effect from 1 September 2023, and as further amended or replaced from time to time.
      • “UK GDPR” means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as further defined in section 3(10) of the Data Protection Act 2018 (supplemented by section 205(4) of that Act).

Annex 1: Details of processing

This Annex sets out the details of processing required by Article 28(3) UK GDPR. Annex 2 below separately completes the Standard Contractual Clauses and International Data Transfer Addendum referred to in the clause about ‘International transfers’ above, for any transfer where that clause applies.

A. Parties

Exporter/Controller (or processor, where the clause about ‘Roles’ above applies): the Client named on your order form or sign-up confirmation. Importer/Processor: the Agilio Group company named in your order form or sign-up confirmation for the product you use. Contact details for both parties are as set out in your order form or sign-up confirmation and our General Terms.

B. Subject matter, nature and duration of processing

Subject matter: provision of the services described in your order form and Product-Specific Terms, including your subscribed services and any statement of work. Nature and purpose: hosting, storage, transmission and other processing of personal data reasonably necessary to provide those services, carried out on your documented instructions as defined in the clause about ‘Definitions’ above. Duration: for the term of your subscription (and any related statement of work), and thereafter as set out in the clause about ‘When your contract ends’ above.

C. Categories of data subjects and personal data

The following are the categories of data subjects and personal data we typically process on your behalf, across our products.

Categories of data subjects Categories of personal data
Your staff and team membersContact details; employment, training and CPD records (including professional registration numbers); compliance and audit records; and, where you choose to record it, equality, diversity and inclusion (EDI) monitoring data.
Your patients and prospective patientsContact, appointment and practice-relationship data (including plan or membership status); enquiry data; communications content; and health or treatment-related data submitted or generated in connection with patient engagement, recall or membership features, including behavioural or engagement data generated by AI-enabled features.
Patients and colleagues providing feedback through a productContact details and feedback content submitted through appraisal, CPD or reflective-practice features — this may include health-related or patient-identifiable information. Where one of these features uses AI to help draft or summarise that content — for example, a reflection or development plan — this also includes the resulting AI-drafted content.
Individuals paying by Direct Debit or another payment methodContact and payment details, including bank account details for payment collection.

D. Frequency, retention and sub-processors

Frequency: continuous, for the duration of your subscription. Retention: as set out in the clause about ‘When your contract ends’ above. Sub-processors: as listed on our Sub-Processors page, updated from time to time in line with the clause about ‘Sub-processors’ above.

E. Competent supervisory authority

Where the UK GDPR applies, the Information Commissioner’s Office. Where the EU GDPR applies, the supervisory authority for the EU member state in which you’re established (or, if you have no EU establishment, the authority determined in accordance with Article 27 EU GDPR and the arrangements referred to in the clause about ‘Compliance’ above). Where the Swiss FADP applies, the Federal Data Protection and Information Commissioner (FDPIC).

Annex 2: International transfers — Standard Contractual Clauses and UK Addendum

Where the clause about ‘International transfers’ above applies to a specific transfer of your personal data, this Annex 2 completes the relevant transfer mechanism for that transfer, in addition to Annex 1 above.

A. Which Clauses and modules apply

Where the transfer is from the EEA (or is otherwise subject to the EU GDPR), the version of the European Commission’s Standard Contractual Clauses currently in force (Decision (EU) 2021/914) applies, using whichever of the following modules matches the transfer in question: Module Two (Controller to Processor), where you’re the controller and we export your personal data to a sub-processor as processor; or Module Three (Processor to Processor), where you’re a processor for your own third-party controller under the clause about ‘Roles’ above, and we, as your sub-processor, export personal data to our own sub-processor. The optional docking clause (Clause 7 of the Standard Contractual Clauses) doesn’t apply — the parties to each transfer are fixed as set out in Annex 1.A above. Clause 17 (governing law) and Clause 18(b) (choice of forum) of the Standard Contractual Clauses are completed with the law and courts of Ireland, the conventional default where neither party is established in an EU member state.

B. UK transfers — International Data Transfer Addendum

Where the transfer is from the UK, the Clauses above apply as modified by the UK Information Commissioner’s International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (the "UK Addendum"), in the form issued by the Information Commissioner and in force from time to time. The UK Addendum’s own Tables 1 to 4 are completed as follows: Table 1 (Parties) — as set out in Annex 1.A above. Table 2 (Selected Clauses, Modules and Selected Clauses) — the module identified in paragraph A above, with no optional clauses selected other than as stated in paragraph A. Table 3 (Annex Information) — Annex I.A, I.B and I.C of the Clauses are completed with the information in Annex 1.A, Annex 1.B to 1.D, and Annex 1.E above respectively, and Annex II of the Clauses (technical and organisational measures) is completed with the information in paragraph D below. Table 4 (Ending the UK Addendum when the Approved Addendum changes) — we may end the UK Addendum as set out in Section 19 of the UK Addendum if the Information Commissioner issues a revised Approved Addendum, by giving you written notice.

C. Completion of the Clauses' own Annexes (non-UK transfers)

Where a transfer is governed by the Clauses directly, rather than through the UK Addendum, the Clauses' own Annex I.A (List of Parties), Annex I.B (Description of Transfer) and Annex I.C (Competent Supervisory Authority) are completed with the information in Annex 1.A, Annex 1.B to 1.D, and Annex 1.E above respectively, and Annex II (technical and organisational measures) is completed with the information in paragraph D below.

D. Technical and organisational measures (Annex II)

The following measures apply generally across the Agilio Group's processing of your personal data, in addition to the security measures described in the clause about ‘Security measures’ above:

 

Category Summary of measures
Organisational securityA documented information security policy; mandatory staff training and confidentiality obligations; defined roles and responsibilities for data protection and security.
Access control and authenticationRole-based access on a least-privilege basis; multi-factor authentication for administrative and remote access; periodic access reviews.
EncryptionPersonal data encrypted in transit (TLS) and at rest, using industry-standard algorithms.
Network and infrastructure securityFirewalls and network segmentation; intrusion detection and prevention; regular vulnerability scanning and penetration testing.
Business continuity and backupRegular backups; tested disaster recovery and business continuity arrangements.
Incident responseDocumented breach detection, investigation and notification procedures (see the clause about ‘Breach notification’ above).
Physical and environmental securityHosted on cloud infrastructure providers that maintain independently certified physical and environmental security controls.
Sub-processor oversightDue diligence before engagement, and contractual flow-down of equivalent protections (see the clause about ‘Sub-processors’ above).
Data minimisation and pseudonymisationApplied where practicable, having regard to the nature of the processing and the state of the art.

Details of our current security certifications are available on request through our usual customer support channels.