Data processing agreement

Jurisdiction module: United Kingdom. Version dated 22 August 2026. Your Order Form and any signed addendum take priority where they expressly differ.

Effective 22 August 2026. This DPA forms part of the agreement between Customer as controller (and, where applicable, processor) and the Sulaia contracting entity identified in your Order Form as processor or sub-processor. It applies to personal data processed to provide Sulaia and is intended to meet UK GDPR Article 28.

Details and instructions

Subject matter: hosted clinic operations, communications, booking, care support, reporting and contracted integrations. Duration: the agreement plus the deletion or return period. Nature: collection, hosting, organisation, retrieval, transmission, support, backup and deletion. Data subjects include patients, prospective patients, relatives, staff, practitioners, suppliers and Customer contacts. Data may include identity, contact, appointment, billing, consent, communication, image and clinical/health data. We process only documented instructions in the agreement, Order Form, product configuration and lawful support requests, and tell Customer if an instruction appears unlawful unless prohibited.

Confidentiality, security and incidents

Authorised personnel are bound by confidentiality. Measures include tenant isolation, least-privilege role controls, privileged MFA, encryption in transit, credential and secret controls, audit logging, dependency and vulnerability checks, backup and recovery controls, availability monitoring, incident handling and periodic testing proportionate to risk. We notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer data, provide information reasonably available for Customer's assessment and notifications, mitigate harm, preserve evidence and cooperate with remediation. Customer remains responsible for secure configuration, users, endpoints and lawful data minimisation.

Sub-processors and restricted transfers

Customer gives general authorisation for sub-processors listed in the current register available from the privacy contact identified in your Order Form. We conduct diligence, impose data-protection duties no less protective than this DPA and remain responsible for their performance. We give reasonable advance notice of a material new sub-processor so Customer may object on substantiated data-protection grounds; if no reasonable alternative exists, either party may end the affected service. International transfers use UK adequacy or an approved safeguard such as the UK Addendum/IDTA, plus supplementary measures where required.

Assistance, return, deletion and audit

Taking account of the processing, we assist Customer with data-subject requests, security, breach assessment, DPIAs and regulator consultation. At termination and on Customer's choice, we return or delete Customer personal data, including copies as backup cycles expire, unless law requires storage. We make compliance information available and permit a reasonable audit no more than annually, or after a material incident, subject to confidentiality, security and cost protections; independent reports may satisfy routine requests. Contact the privacy contact identified in your Order Form.