Data processing agreement
Last updated 29 September 2026
This Data Processing Agreement (“DPA”) is incorporated into our Terms of Service for customers on paid plans. It sets out the terms required by Article 28 of the UK GDPR under which RELENTX LTD (trading as ManagePatients, the “Processor”) processes personal data on behalf of the customer (the “Controller”). If there is a conflict between this DPA and the Terms, this DPA prevails in relation to personal data.
1. Definitions
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, and, where they apply, the EU GDPR and other applicable laws. Terms such as “controller”, “processor”, “personal data”, “special category data”, “data subject” and “personal data breach” have the meanings given in the UK GDPR. “Customer Personal Data” means personal data we process on your behalf in providing the service.
2. Details of the processing
| Item | Description |
|---|---|
| Subject matter | Provision of the ManagePatients booking and practice-management service to the Controller. |
| Duration | The term of the Controller’s subscription, plus the 30-day deletion period in section 9. |
| Nature | Collection, recording, organisation, storage, retrieval, use, transmission (by email and SMS), display, export and deletion, by automated means. |
| Purpose | Enabling the Controller to take bookings, manage appointments and patient records, collect forms and consents, send reminders and messages, take payments and issue invoices. |
| Categories of data | Identity and contact details; date of birth; appointment and booking details; home-visit addresses; payment and invoice details; communications; marketing preferences and consents; and special category data concerning health — consultation and consent form answers, medical history, clinical notes, treatment records, images and documents. |
| Data subjects | The Controller’s patients and clients (and their parents or guardians where relevant); prospective patients; the Controller’s staff and practitioners. |
3. Controller obligations
The Controller is responsible for having a lawful basis (and, for health data, an Article 9 condition) for the processing, for giving data subjects the required privacy information, for the lawfulness of its instructions, and for the accuracy of the data it enters.
4. Processor obligations
The Processor will:
- process Customer Personal Data only on the Controller’s documented instructions (the Terms, this DPA and the Controller’s use and configuration of the service are its instructions), unless required by law — in which case it will inform the Controller first unless the law prohibits this;
- tell the Controller if, in its opinion, an instruction infringes Data Protection Law;
- ensure that everyone authorised to process Customer Personal Data is under a duty of confidentiality;
- implement the security measures in section 6;
- not sell Customer Personal Data or use it for its own purposes, including marketing or training models;
- comply with the conditions for engaging sub-processors in section 5.
5. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors. The current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication and file storage (all account and patient data) | EU — Ireland (AWS eu-west-1) |
| Vercel Inc. | Application hosting, serverless functions and content delivery | Global edge network; US-headquartered |
| Stripe Payments Europe / Stripe Inc. | Subscription billing for clinics; card payments and deposits taken by clinics from patients | EU / UK / US |
| Twilio Inc. | SMS delivery (reminders, confirmations, two-way messages) | US / global carrier network |
| Resend (Plus Five Five Inc.) | Transactional email delivery | US |
| Google LLC (Google Maps Platform) | Address lookup, geocoding and travel-distance calculation for home visits | US / global |
| Easy Postcodes | UK postcode and address lookup | UK |
| Functional Software Inc. (Sentry) | Error monitoring and diagnostics (limited technical data) | US |
| Upstash Inc. | Rate limiting to protect booking and sign-in forms (IP address only) | Region to be confirmed |
The Processor will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains liable for their performance. The Processor will notify the Controller by email at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected service and receive a pro-rata refund of prepaid fees.
6. Security measures
Taking into account the nature of the data, including health data, the Processor maintains measures including:
- encryption of data in transit (TLS) and at rest;
- hosting of the primary database in the EU (Ireland) with a reputable cloud provider;
- logical separation of each customer’s data enforced by database row-level security;
- role-based access controls within each account, and restriction of Processor staff access to what is needed for support and operations;
- audit logging of key actions within customer accounts;
- rate limiting and monitoring to detect abuse and errors;
- regular backups provided by the hosting provider;
- secure development practices, dependency updates and review of security-relevant changes.
7. Personal data breaches
The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences and the measures taken or proposed. The Processor will provide further information as it becomes available and will take reasonable steps to contain and remedy the breach.
8. Assistance
Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller with:
- responding to data subject requests (access, rectification, erasure, restriction, portability, objection) — much of which the Controller can do itself through the dashboard, including patient export and erasure requests. The Processor will pass on any request it receives directly;
- security, breach notification to the ICO and to data subjects;
- data protection impact assessments and prior consultation with the ICO, where required.
9. Deletion or return at the end of the service
The Controller can export its data from the dashboard at any time before its subscription ends. Within 30 days after the subscription is cancelled or ends, the Processor will delete Customer Personal Data, unless UK law requires it to be retained. Data held in backups is overwritten in line with the backup rotation cycle and is not restored except for disaster recovery.
10. Audits and information
The Processor will make available the information reasonably necessary to demonstrate compliance with Article 28 and this DPA, and will allow for and contribute to audits, including inspections, by the Controller or an auditor it appoints. Audits must be requested with at least 30 days’ written notice, take place during business hours no more than once a year (unless following a personal data breach or required by a regulator), and be subject to confidentiality. The Processor may first respond with documentation, questionnaires or third-party certifications of its sub-processors.
11. International transfers
The Processor will not transfer Customer Personal Data outside the UK unless the transfer complies with Data Protection Law — to a country covered by UK adequacy regulations (including the EEA, and the United States for organisations certified to the UK Extension to the EU–US Data Privacy Framework), or subject to appropriate safeguards such as the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with any supplementary measures needed. Where EU GDPR applies to the Controller, the EU Standard Contractual Clauses apply where applicable.
12. Liability and term
Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not permit this. This DPA remains in force for as long as the Processor processes Customer Personal Data on the Controller’s behalf.
Contact
Data protection questions and notices under this DPA: hello@managepatients.com. RELENTX LTD, 128 City Road, London, EC1V 2NX. If you need a countersigned copy of this DPA for your records, email us.