DATA PROCESSING AGREEMENT
Important jurisdiction and regulatory warning
This fictional agreement is a worked example for discussion and is not legal advice or a universally valid data processing agreement. It is written for a controller and processor operating in England and Wales. The UK GDPR, Data Protection Act 2018, international-transfer rules, sector regulation and Information Commissioner's Office guidance may require additional terms. Obtain current advice and check the actual processing, formalities, security measures, transfers and special-category data before signing.
1. Parties and effective date
This agreement is made on 14 October 2026 between Harbourlight Community Clinics Ltd, company number 11984620, of 18 Calder Street, Leeds LS2 7JP (the Controller), and Northstar Appointment Systems Ltd, company number 13250741, of 42 Meridian Park, York YO26 6RW (the Processor). It applies from 1 November 2026 to their services agreement dated 30 September 2026.
The Controller operates private physiotherapy clinics. The Processor supplies a hosted appointment, reminder and customer-support platform. The Controller determines the purposes and means of processing, and the Processor acts only on documented instructions. Neither party transfers a responsibility that law places on that party.
2. Processing details and instructions
The Processor may receive names, addresses, contact details, appointment dates, clinic attendance information, accessibility requests, payment references and communications. Some notes may reveal physical health information. The data concerns patients, prospective patients, carers, staff contacts and suppliers. Processing is limited to hosting records, administering bookings, sending reminders, answering support requests, producing agreed reports and maintaining security.
The processing lasts for the term of the services agreement and any limited period needed to return or delete data. The Controller's written instructions are this agreement, the services statement dated 30 September 2026, written tickets authorised by a named Controller contact, and later written instructions that do not conflict with law. The Processor must tell the Controller if an instruction appears to breach applicable data protection law and must not use the data for advertising, profiling for its own purposes, sale, or any unrelated product development.
The Controller will ensure that its notices, lawful bases, consent records where required, retention periods and instructions are suitable, provide reasonably accurate data, and answer Processor questions about rights requests. These obligations do not make it responsible for a failure caused solely by the Processor's breach.
3. Confidentiality and personnel
The Processor must keep personal data confidential and ensure that its employees, temporary staff and contractors who may access it are bound by confidentiality duties. Access must be limited to people who need it for the services. The Processor will provide appropriate training and maintain access records. A person who leaves the Processor or no longer needs access must have access removed promptly.
4. Security measures
The Processor will maintain risk-appropriate technical and organisational measures, including unique accounts, multi-factor authentication for administrative access, encryption in transit and backups, role-based permissions, malware protection, vulnerability management, tested restoration, physical controls and security logging. It will test continuity and recovery at least annually.
The Processor will give a current security summary on reasonable request, subject to protecting sensitive security information. It must notify the Controller without undue delay after becoming aware of a personal data breach and provide available information about its nature, consequences, affected data and remedial action. The Controller decides whether to notify the Information Commissioner's Office or individuals, unless law provides otherwise.
5. Sub-processors and international access
The Controller gives general written authorisation for the Processor to use Cloudmere Hosting Ltd, of 7 Riverside Exchange, Manchester M3 4EN, for encrypted infrastructure hosting, and Belltower Messaging Ltd, of 11 Kingfisher Way, Bristol BS1 5TR, for text-message delivery. The Processor must give at least thirty days' written notice of a proposed material change. The Controller may object on reasonable data-protection grounds. The Processor must impose written obligations on each sub-processor that provide materially equivalent protection and remains responsible for its sub-processor's performance.
The Processor must not permit access to or transfer of personal data outside the United Kingdom unless the Controller has approved the arrangement in writing and the Processor has completed any required adequacy, appropriate safeguards, transfer-risk assessment and supplementary-measures steps. Remote support access is treated as an international transfer where applicable.
6. Rights requests, complaints and assistance
The Processor must promptly forward a data subject request or complaint to the Controller and must not answer it except on the Controller's written instructions or where law requires an answer. Taking account of the processing, the Processor will reasonably assist with access, rectification, erasure, restriction, portability, objection, security assessments, breach investigations, consultations and regulatory enquiries. The Controller will reimburse reasonable, documented assistance costs where the request is unusual and not caused by Processor fault.
7. Audit, retention and return
The Processor will keep compliance records and provide reasonable audit information. Once each year, the Controller may review an independent security report or conduct a proportionate remote audit on fifteen business days' notice. An on-site audit is permitted for a regulatory request, serious incident or apparent material non-compliance, subject to confidentiality and reasonable disruption limits.
At the Controller's choice when the services end, the Processor will return the personal data in a commonly used format and then securely delete its copies within thirty days, except where law requires retention. It will tell the Controller when deletion is complete and keep retained data protected, inaccessible for other use, and deleted when the retention duty ends. Backups will be overwritten through the Processor's ordinary cycle, which must not exceed ninety days.
8. Liability, precedence and signatures
The services agreement's liability terms apply subject to any liability that cannot lawfully be limited. If this agreement conflicts with a mandatory data protection requirement, that requirement prevails. A change to processing instructions or this agreement must be written and signed by authorised representatives.
For Harbourlight Community Clinics Ltd:
Name: Eleanor Ruth Maddox, Chief Operating Officer
Signature: ____________________ Date: 14 October 2026
For Northstar Appointment Systems Ltd:
Name: Daniel Imran Shah, Managing Director
Signature: ____________________ Date: 14 October 2026
Each signatory confirms authority to sign.