Draft — pending legal review.This document is being reviewed by our solicitor and may change before it is finalised.
Legal

Data processing agreement

Last updated 29 September 2026

This Data Processing Agreement (“DPA”) is incorporated into our Terms of Service for customers on paid plans. It sets out the terms required by Article 28 of the UK GDPR under which RELENTX LTD (trading as ManagePatients, the “Processor”) processes personal data on behalf of the customer (the “Controller”). If there is a conflict between this DPA and the Terms, this DPA prevails in relation to personal data.

1. Definitions

“Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, and, where they apply, the EU GDPR and other applicable laws. Terms such as “controller”, “processor”, “personal data”, “special category data”, “data subject” and “personal data breach” have the meanings given in the UK GDPR. “Customer Personal Data” means personal data we process on your behalf in providing the service.

2. Details of the processing

ItemDescription
Subject matterProvision of the ManagePatients booking and practice-management service to the Controller.
DurationThe term of the Controller’s subscription, plus the 30-day deletion period in section 9.
NatureCollection, recording, organisation, storage, retrieval, use, transmission (by email and SMS), display, export and deletion, by automated means.
PurposeEnabling the Controller to take bookings, manage appointments and patient records, collect forms and consents, send reminders and messages, take payments and issue invoices.
Categories of dataIdentity and contact details; date of birth; appointment and booking details; home-visit addresses; payment and invoice details; communications; marketing preferences and consents; and special category data concerning health — consultation and consent form answers, medical history, clinical notes, treatment records, images and documents.
Data subjectsThe Controller’s patients and clients (and their parents or guardians where relevant); prospective patients; the Controller’s staff and practitioners.

3. Controller obligations

The Controller is responsible for having a lawful basis (and, for health data, an Article 9 condition) for the processing, for giving data subjects the required privacy information, for the lawfulness of its instructions, and for the accuracy of the data it enters.

4. Processor obligations

The Processor will:

  • process Customer Personal Data only on the Controller’s documented instructions (the Terms, this DPA and the Controller’s use and configuration of the service are its instructions), unless required by law — in which case it will inform the Controller first unless the law prohibits this;
  • tell the Controller if, in its opinion, an instruction infringes Data Protection Law;
  • ensure that everyone authorised to process Customer Personal Data is under a duty of confidentiality;
  • implement the security measures in section 6;
  • not sell Customer Personal Data or use it for its own purposes, including marketing or training models;
  • comply with the conditions for engaging sub-processors in section 5.

5. Sub-processors

The Controller gives general authorisation for the Processor to engage sub-processors. The current sub-processors are:

Sub-processorPurposeLocation
Supabase Inc.Database, authentication and file storage (all account and patient data)EU — Ireland (AWS eu-west-1)
Vercel Inc.Application hosting, serverless functions and content deliveryGlobal edge network; US-headquartered
Stripe Payments Europe / Stripe Inc.Subscription billing for clinics; card payments and deposits taken by clinics from patientsEU / UK / US
Twilio Inc.SMS delivery (reminders, confirmations, two-way messages)US / global carrier network
Resend (Plus Five Five Inc.)Transactional email deliveryUS
Google LLC (Google Maps Platform)Address lookup, geocoding and travel-distance calculation for home visitsUS / global
Easy PostcodesUK postcode and address lookupUK
Functional Software Inc. (Sentry)Error monitoring and diagnostics (limited technical data)US
Upstash Inc.Rate limiting to protect booking and sign-in forms (IP address only)Region to be confirmed

The Processor will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains liable for their performance. The Processor will notify the Controller by email at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected service and receive a pro-rata refund of prepaid fees.

6. Security measures

Taking into account the nature of the data, including health data, the Processor maintains measures including:

  • encryption of data in transit (TLS) and at rest;
  • hosting of the primary database in the EU (Ireland) with a reputable cloud provider;
  • logical separation of each customer’s data enforced by database row-level security;
  • role-based access controls within each account, and restriction of Processor staff access to what is needed for support and operations;
  • audit logging of key actions within customer accounts;
  • rate limiting and monitoring to detect abuse and errors;
  • regular backups provided by the hosting provider;
  • secure development practices, dependency updates and review of security-relevant changes.

7. Personal data breaches

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences and the measures taken or proposed. The Processor will provide further information as it becomes available and will take reasonable steps to contain and remedy the breach.

8. Assistance

Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller with:

  • responding to data subject requests (access, rectification, erasure, restriction, portability, objection) — much of which the Controller can do itself through the dashboard, including patient export and erasure requests. The Processor will pass on any request it receives directly;
  • security, breach notification to the ICO and to data subjects;
  • data protection impact assessments and prior consultation with the ICO, where required.

9. Deletion or return at the end of the service

The Controller can export its data from the dashboard at any time before its subscription ends. Within 30 days after the subscription is cancelled or ends, the Processor will delete Customer Personal Data, unless UK law requires it to be retained. Data held in backups is overwritten in line with the backup rotation cycle and is not restored except for disaster recovery.

10. Audits and information

The Processor will make available the information reasonably necessary to demonstrate compliance with Article 28 and this DPA, and will allow for and contribute to audits, including inspections, by the Controller or an auditor it appoints. Audits must be requested with at least 30 days’ written notice, take place during business hours no more than once a year (unless following a personal data breach or required by a regulator), and be subject to confidentiality. The Processor may first respond with documentation, questionnaires or third-party certifications of its sub-processors.

11. International transfers

The Processor will not transfer Customer Personal Data outside the UK unless the transfer complies with Data Protection Law — to a country covered by UK adequacy regulations (including the EEA, and the United States for organisations certified to the UK Extension to the EU–US Data Privacy Framework), or subject to appropriate safeguards such as the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with any supplementary measures needed. Where EU GDPR applies to the Controller, the EU Standard Contractual Clauses apply where applicable.

12. Liability and term

Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not permit this. This DPA remains in force for as long as the Processor processes Customer Personal Data on the Controller’s behalf.

Contact

Data protection questions and notices under this DPA: hello@managepatients.com. RELENTX LTD, 128 City Road, London, EC1V 2NX. If you need a countersigned copy of this DPA for your records, email us.