Legal
Data Processing Agreement
- Version
- 1.0
- Last updated
- 20 September 2026
- Between
- And
- Effective date
- The date on which the Controller accepted the Platform Terms of Service, which incorporate this Agreement at clause 6.3. That date, the accepting account and the exact version of this Agreement accepted are recorded by the Processor.
Bailey & Prosper Holdings Ltd (registered in England and Wales, company number 17444004, ICO registration pending; registration is in progress and will be in place before the first clinic is onboarded), 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ ("Processor")
The Subscriber identified in the Platform account through which these terms were accepted, at the address recorded in that account ("Controller")
Background
The Controller is a healthcare practitioner or clinic who uses the Processor's practice management platform (the "Platform") to manage patient records, appointments, and clinical documentation.
In providing the Platform, the Processor processes personal data (including special category health data) on behalf of the Controller. This Data Processing Agreement sets out the obligations of both parties in respect of that processing, as required by Article 28 of the UK General Data Protection Regulation ("UK GDPR").
This Agreement supplements and forms part of the Platform Terms of Service between the parties.
Part 1: Processing Details
| Controller name | The Subscriber named on the Platform account that accepted these terms |
| Controller address | The address recorded on that account |
| Controller ICO registration | The registration recorded on that account, which the Subscriber warrants is current (clause 6.4 of the Terms of Service) |
| Controller contact for data protection | The administrator contact recorded on that account |
| Processor name | Bailey & Prosper Holdings Ltd |
| Processor ICO registration | registration pending |
Subject matter of processing
The Processor will process personal data on behalf of the Controller for the purpose of providing the Platform, a web-based practice management system for healthcare practitioners.
Nature of processing
Storage, retrieval, organisation, transmission, deletion, and restriction of personal data as initiated by the Controller through their use of the Platform.
Purpose of processing
To enable the Controller to manage their healthcare practice, including patient registration, appointment booking, clinical note-keeping, consent form management, invoicing, and patient communications.
Duration of processing
For the term of the Platform Terms of Service, and thereafter for the applicable mandatory retention period for clinical records (minimum 8 years for adult patients under HCPC standards).
Categories of data subjects
- Patients of the Controller
- Staff and practitioners of the Controller
Categories of personal data
- Patient personal details (name, date of birth, address, contact details)
- Medical history and health conditions
- Clinical notes and treatment records
- Consent forms and digital signatures
- Appointment history
- Invoice and payment records
- GP and referral details
- Emergency contact details
Special categories of personal data
Health data within the meaning of Article 9(1) UK GDPR, including physical and mental health records, clinical assessments, treatment notes, and consent forms relating to patients of the Controller.
Part 2: Obligations of the Processor
1. Processing on instructions only
The Processor shall process personal data only on documented instructions from the Controller. The Platform Terms of Service and this Agreement constitute the Controller's instructions. The Processor shall inform the Controller if, in its opinion, an instruction infringes UK GDPR or other applicable data protection law.
2. Confidentiality
The Processor shall ensure that persons authorised to process personal data under this Agreement are bound by appropriate confidentiality obligations.
3. Security
The Processor shall implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Mandatory multi-factor authentication for all practitioner accounts
- Row-level security at the database layer enforcing tenant isolation
- Comprehensive audit logging of all access to clinical data
- Rate limiting on all API endpoints
- Private storage buckets with signed URLs (15-minute expiry)
- Regular security reviews and penetration testing (before second paying tenant)
4. Sub-processors
The Processor uses the following sub-processors:
| Sub-processor | Purpose | Location | DPA in place |
|---|---|---|---|
| Supabase, Inc | Database and storage | EU (London) | ✅ |
| Vercel, Inc | Application hosting | Global | ✅ |
| Resend (Plus Five Five, Inc) | Transactional email | United States | ✅ |
| Upstash, Inc | Rate limiting | EU | ✅ |
The Processor will notify the Controller at least 30 days before engaging any new sub-processor. The Controller may object to a new sub-processor within 14 days of notice on reasonable data protection grounds. If the parties cannot reach a mutually acceptable resolution, the Controller may terminate the Agreement.
5. Data subject rights
The Processor shall assist the Controller in responding to data subject rights requests, to the extent technically feasible and within the self-service functionality of the Platform. The Processor shall promptly notify the Controller of any data subject request it receives directly in relation to the Controller's patient data.
6. Data protection impact assessment
The Processor shall provide reasonable assistance to the Controller where a data protection impact assessment is required under Article 35 UK GDPR in connection with the processing carried out under this Agreement.
7. Personal data breaches
The Processor shall notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the Controller's data. The Processor shall provide all information reasonably necessary to enable the Controller to fulfil its notification obligations to the ICO and to affected data subjects.
8. Deletion and return of data
On termination of the Platform Terms of Service:
- The Controller may request an export of their data within 30 days of termination. The Processor will provide a structured export in a machine-readable format.
- The Processor will retain clinical records for the applicable mandatory retention period (minimum 8 years for HCPC-regulated records) even after termination, as required by law.
- After the mandatory retention period expires, the Processor will permanently delete all personal data unless otherwise instructed.
9. Audits and compliance
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this Agreement. The Controller may audit the Processor's compliance with this Agreement no more than once per calendar year on 30 days written notice, at the Controller's cost.
Part 3: Obligations of the Controller
The Controller warrants and undertakes that:
- It holds a valid ICO registration that covers the processing of special category health data
- It has a lawful basis for processing patient health data (typically Article 9(2)(h) UK GDPR: processing necessary for the provision of health care)
- It provides patients with an appropriate privacy notice before collecting their personal data
- It responds to data subject rights requests from its patients in accordance with UK GDPR
- It maintains records of its processing activities as required by Article 30 UK GDPR
- It has appropriate professional indemnity insurance in place
- It will only use the Platform for lawful healthcare practice management purposes
Part 4: International Transfers
Patient data is stored in Supabase's eu-west-2 region (London, United Kingdom). Transactional emails are delivered via Resend, which is based in the United States. This transfer is covered by Standard Contractual Clauses and the EU-US Data Privacy Framework.
Part 5: Signatures
By signing below, both parties agree to the terms of this Data Processing Agreement.
Controller
Signed: ___________________________
Name: ___________________________
Position: ___________________________
Organisation: ___________________________
Date: ___________________________
Processor
Signed: ___________________________
Name: Andy Lawson
Position: Director
Organisation: Bailey & Prosper Holdings Ltd
Date: ___________________________
This Agreement is governed by the laws of England and Wales.
Any disputes arising from this Agreement shall be subject to the exclusive jurisdiction of the courts of England and Wales.