This Data Processing Agreement (“Agreement”) forms part of the Terms & Conditions of Supply between:
- the Customer named in the Order (the “Controller”); and
- Tree View Designs Ltd (registered in England and Wales as Tree View Designs Limited, company number 06975947), whose registered office is at 46 Skylark Lane, Whitfield, Dover, England, CT16 3QR (the “Processor”).
This Agreement applies where, and to the extent that, the Processor Processes Personal Data on behalf of the Controller in the provision of the Services. Where the Customer contracts on behalf of Member Practices, clause 1.6 applies and each Member Practice is a Controller in respect of the Personal Data Processed through its own Site.
1. Definitions and Interpretation
1.1 Capitalised terms used in this Agreement shall have the meanings given to them in the Terms & Conditions of Supply (including Add-on Services, Business Day, Charges, Contract, Customer, Customer Data, Designated Contact, Digital Triage Features, Normal Business Hours, Order, Services and Site), unless otherwise defined in this Agreement.
1.2 In this Agreement, the following definitions apply:
- Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing
- Have the meanings given in Article 4 UK GDPR, and “Process” and “Processed” shall be construed accordingly. References to the Controller include, where clause 1.6 applies, each Member Practice in respect of the Personal Data Processed through its own Site.
- Data Protection Legislation
- The UK GDPR and the Data Protection Act 2018, each as amended from time to time (including by the Data (Use and Access) Act 2025); the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended from time to time; any legislation that replaces or succeeds them in the United Kingdom; and applicable guidance and codes of practice issued by the Information Commissioner’s Office (ICO).
- Digital Triage Features
- Has the meaning given in the Terms & Conditions of Supply, being the SmartForms, PatientInbox and PatientPortal features of the Site.
- domestic law
- The law of the United Kingdom or of a part of the United Kingdom, as that expression is used in the UK GDPR.
- Member Practice
- Has the meaning given in the Terms & Conditions of Supply, being an organisation identified in the Order as a practice for which the Customer contracts and for which a Site is provided under the Contract, other than the Customer itself.
- Restricted Transfer
- A transfer of Personal Data to, or the Processing of Personal Data by any person located in, a country or territory outside the United Kingdom, or a transfer of Personal Data to an international organisation, within the meaning of Chapter V of the UK GDPR.
- Special Category Data
- Personal Data the Processing of which is subject to the prohibition in Article 9(1) UK GDPR, including data concerning health.
- Sub-processor
- Any processor engaged by the Processor, or by another Sub-processor, to carry out specific Processing activities on behalf of the Controller in connection with the Services.
- UK GDPR
- Has the meaning given in section 3(10) of the Data Protection Act 2018.
1.3 Where there is any conflict between the definitions in this Agreement and the Terms & Conditions of Supply, the definitions in this Agreement shall prevail solely in respect of data protection matters.
1.4 References to applicable law include all guidance, codes of practice, and regulatory requirements issued by the Information Commissioner’s Office (ICO), NHS England, or any successor bodies where relevant.
1.5 This Agreement is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
1.6 Where the Customer contracts on behalf of Member Practices identified in the Order:
- each Member Practice is the Controller of the Personal Data Processed through its own Site, and the Customer is the Controller of the Personal Data Processed through any Site provided for the Customer itself;
- this Agreement applies between the Processor and each Member Practice as Controller in respect of its own Site, the Customer having confirmed and warranted under clause 4.10 of the Terms & Conditions of Supply that it has the authority of each Member Practice to enter into the Contract, including this Agreement, on its behalf and that each Member Practice has agreed to be bound by it; where the Customer does not have that authority, the Customer shall be treated as the Controller of the Personal Data concerned as between the parties, without prejudice to the Processor’s other rights;
- instructions given to the Processor by the Customer, or by a Designated Contact, in respect of a Member Practice’s Site are documented instructions of that Member Practice as Controller, and the Processor may rely on them;
- the Processor’s obligations under clauses 6, 7, 8, 11 and 12 are owed to the Controller of the Personal Data concerned, and the Processor may in addition notify the Customer to the extent necessary for the Customer to coordinate the response;
- the rights of the Controller under clauses 4, 9, 13 and 14 shall be exercised by the Customer on behalf of itself and all Member Practices together, and one audit or inspection under clause 9 in any 12-month period shall satisfy the Processor’s obligations to all of them;
- the limitation of liability in clause 9.3 of the Terms & Conditions of Supply applies to the Processor’s total aggregate liability to the Customer and all Member Practices together; and
- the Processor acts only on the documented instructions of the Controller under clause 3.1 and is not party to any arrangement between the Customer and any Member Practice, or between Member Practices, as to their respective responsibilities under the Data Protection Legislation, including any arrangement under Article 26 UK GDPR.
1.7 References to a clause or Schedule are to a clause of, or Schedule to, this Agreement unless otherwise stated. References to a clause of the Terms & Conditions of Supply are to that clause as numbered in the version of the Terms & Conditions of Supply forming part of the Contract. The word “including” means including without limitation.
2. Scope, Subject Matter, and Duration
2.1 This Agreement applies for the duration of the Services involving the Processing of Personal Data and, notwithstanding any notice under clause 13, shall continue in force until the Processor has completed the secure return or deletion of all Personal Data in accordance with clause 11, whereupon it shall automatically terminate.
2.2 The subject matter, nature, purpose, duration of Processing, retention arrangements, categories of Personal Data, and categories of Data Subjects are set out in Schedule 1.
2.3 The Processor shall not Process Personal Data for any purpose other than the provision of the Services, unless required to do so by domestic law, in which case clause 3.1(a) applies.
2.4 For the avoidance of doubt, the Processor acts as an independent controller of the business contact details and correspondence of the Controller’s staff that it holds for its own account administration, billing, helpdesk and training purposes, as described in the Processor’s privacy notice, and this Agreement does not apply to that processing. This clause does not affect any Personal Data of patients or other Data Subjects contained in such correspondence, or staff details and user accounts that the Processor Processes on the Controller’s behalf as part of the Site or the Services, all of which remain subject to this Agreement.
3. Processor and Controller Obligations
3.1 The Processor shall:
- Process Personal Data only on documented instructions from the Controller, including with regard to any transfer of Personal Data outside the United Kingdom or to an international organisation, unless required to do so by domestic law; in that case the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits the Processor from informing the Controller on important grounds of public interest. The Controller’s documented instructions comprise this Agreement (including its Schedules), the Terms & Conditions of Supply, the Order, and any further written instructions given by or on behalf of the Controller, including through its Designated Contact, that are consistent with the Contract;
- ensure that persons authorised to Process Personal Data are subject to appropriate confidentiality obligations;
- take all reasonable steps to ensure the reliability, integrity, and appropriate training of personnel who have access to Personal Data;
- implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature of the Processing, and take all measures required by Article 32 UK GDPR;
- take steps to ensure that any natural person acting under its authority who has access to Personal Data does not Process it except on the Controller’s instructions, unless required to do so by domestic law;
- maintain written records of the Processing activities carried out on behalf of the Controller as required by Article 30(2) UK GDPR; and
- not knowingly cause the Controller to breach Data Protection Legislation.
3.2 The Processor shall immediately inform the Controller if, in its opinion, any instruction infringes Data Protection Legislation.
3.3 The Controller shall:
- ensure it has a lawful basis under Article 6 UK GDPR and, for Special Category Data, an applicable condition under Article 9 UK GDPR and Schedule 1 to the Data Protection Act 2018 for the Processing it instructs, as confirmed in clause 8.3 of the Terms & Conditions of Supply;
- ensure its instructions comply with Data Protection Legislation;
- determine which forms, including SmartForms, are published on the Site and what Personal Data they collect;
- administer its own users’ access to Personal Data held in the Site’s control panel, in accordance with clauses 4.1 and 4.5 of the Terms & Conditions of Supply and Article 32(4) UK GDPR, ensuring that access is granted only to persons it has authorised and is removed promptly when no longer required, that persons acting under its authority Process Personal Data only on the Controller’s instructions, and that it notifies the Processor without undue delay on becoming aware of any suspected compromise of a user account;
- provide to Data Subjects the privacy information required by Articles 13 and 14 UK GDPR in respect of the Site, including its forms (including SmartForms) and, where enabled, the PatientInsights feedback form;
- decide, from the options the Processor makes available, which features and storage and access technologies (including analytics and automatic translation) are enabled on the Site and, as between the parties, be responsible for giving Data Subjects the clear and comprehensive information and the consent or simple means of objecting required by regulation 6 of, and Schedule A1 to, the Privacy and Electronic Communications (EC Directive) Regulations 2003, using the consent mechanism the Processor provides under clause 4.4 of the Terms & Conditions of Supply and any other objection mechanism the Processor makes available on the Site;
- notify the Processor of its choices under paragraph (f) through the Designated Contact; and
- remain responsible for the deployment and use of the Site and the Digital Triage Features in its own clinical setting, as set out in clause 4.8 of the Terms & Conditions of Supply, including compliance with the clinical risk management standard DCB0160 where it applies to the Controller, and for all clinical decisions; the Digital Triage Features do not diagnose, triage or prioritise automatically, and the Processor shall provide such clinical safety information as it holds on request.
3.4 The parties acknowledge that Personal Data submitted by patients and other Data Subjects through the Site in the course of the Services may be confidential information about patients subject to the common law duty of confidentiality in addition to the Data Protection Legislation. The Processor shall treat such information as confidential, shall not disclose it except in accordance with the Controller’s documented instructions or as required by law, and shall have regard to the Caldicott Principles published by the National Data Guardian (as amended from time to time) when Processing it. The Processor shall maintain the organisational and technical measures required to meet the National Data Guardian’s data security standards as assessed through the NHS Data Security and Protection Toolkit (or any successor assessment framework published by NHS England), in accordance with clause 6.5.
3.5 The Controller has the rights set out in this Agreement, including to give instructions, object to Sub-processors under clause 4, receive assistance under clause 7 and notifications under clauses 6 and 8, audit under clause 9, require return or deletion under clause 11 and terminate under clause 13. The Processor’s obligations under clause 6.1 apply to the Processor’s own personnel, systems and hosting environment and do not extend to the Controller’s decisions about which of its users are granted access; the Processor remains responsible for providing and maintaining the access-control and authentication features of the Site’s control panel.
4. Sub-processors
4.1 The Controller provides general written authorisation, for the purposes of Article 28(2) UK GDPR, for the Processor to engage Sub-processors of the categories, for the purposes and in the locations set out in Schedule 3 for the provision of the Services. The current named list of Sub-processors, stating the location of Processing and the transfer mechanism relied on for each, is provided to the Controller at contract signature and on request.
4.2 The Processor shall:
- maintain the current named list of Sub-processors, stating for each the service it provides, the categories of Personal Data it may Process and the country or countries in which it Processes Personal Data, and provide the current list to the Controller on request;
- give the Controller at least thirty (30) days’ written notice, by email in accordance with clause 16, of any intended addition or replacement of a Sub-processor, stating the date by which any objection must be raised, save that where a replacement is urgently required to maintain the security, availability or continuity of the Services the Processor may make the change and give notice as soon as reasonably practicable afterwards, and the Controller’s objection rights under paragraph (c) shall apply from that notice;
- where the Controller objects in writing on reasonable data protection grounds before that date, discuss the objection with the Controller in good faith and seek to address it; where the objection cannot reasonably be resolved within thirty (30) days of the Controller’s objection, the Controller may terminate the affected Services on written notice, the Processor shall refund any Charges paid in advance in respect of those Services for the period after termination notwithstanding clause 6.2 of the Terms & Conditions of Supply, and clause 11 shall apply; and
- ensure all Sub-processors are bound by written agreements imposing data protection obligations no less onerous than those set out in this Agreement, as required by Article 28(4) UK GDPR.
4.3 The Processor shall remain fully liable to the Controller for the acts and omissions of its Sub-processors and for the performance of their obligations.
4.4 For the purposes of this Agreement, Sub-processors may include infrastructure, hosting, backup, email delivery, analytics, translation, security, monitoring, or support service providers engaged by the Processor solely to enable the delivery of the Services, as described in Schedule 3. Analytics Sub-processors Process data only where a visitor to the Site has agreed to optional storage and access technologies through the Site’s consent mechanism.
4.5 All Sub-processors act only on the Processor’s documented instructions, are subject to appropriate contractual confidentiality and data protection obligations, and do not acquire any independent rights in the Personal Data.
4.6 The Processor remains fully responsible and liable for the compliance of all Sub-processors with this Agreement.
4.7 For the avoidance of doubt, users given access to a Site’s control panel by or on behalf of the Controller, including administrators of a group, primary care network or federation who publish content to connected Sites using Group Central Management, are not Sub-processors of the Processor. The Processor shall be entitled to treat such users as acting on the Controller’s authority and shall not be liable under this Agreement for their acts or omissions. Nothing in this clause relieves the Processor of its own obligations under clauses 3 and 6. Likewise, a third-party service which the Controller chooses and asks the Processor to add to, or connect with, a Site (for example a chatbot, telephony widget, online consultation tool or embedded feed), or for which the Controller holds its own account with the provider (including the search service used by the Site’s search function), is engaged by the Controller and is not a Sub-processor of the Processor.
5. International Transfers and Hosting
5.1 The Processor shall not make a Restricted Transfer, or permit a Sub-processor to make a Restricted Transfer, except where the Restricted Transfer is:
- covered by adequacy regulations made or having effect under Article 45A UK GDPR (which, at the date of this version of this Agreement, include all countries in the European Economic Area and, for organisations certified to the UK Extension to the EU-US Data Privacy Framework, the United States);
- subject to appropriate safeguards under Article 46 UK GDPR, such as the Information Commissioner’s International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses, where the Processor, acting reasonably and proportionately, has concluded that the data protection test in Article 46 UK GDPR is met; or
- otherwise permitted by Chapter V of the UK GDPR, with the Controller’s prior written authorisation.
5.2 Schedule 3 and the current named list of Sub-processors, as updated under clause 4.2, identify each Sub-processor that Processes Personal Data outside the United Kingdom and the transfer mechanism relied on, and together constitute the Controller’s documented instruction for the purposes of Article 28(3)(a) UK GDPR in respect of the Restricted Transfers described in them. The Processor shall not make a Restricted Transfer to a country or territory not identified in them without first giving notice under clause 4.2, and the Controller may object on the terms set out in that clause.
5.3 The Processor shall keep the transfer mechanism relied on for each Restricted Transfer under review, including where the Information Commissioner issues revised standard data protection clauses, and shall on request provide the Controller with a summary of the mechanism relied on.
5.4 The Site, the Customer Data held on the Processor’s platform, the submissions made through forms on the Site (including through the Digital Triage Features) and the backups of the Site are hosted in data centres located in the United Kingdom. The Processor shall not relocate that hosting or storage outside the United Kingdom without following the notice and objection process in clause 4.2 and complying with clause 5.1.
6. Security Measures, Certifications and Personal Data Breaches
6.1 The Processor shall implement and maintain appropriate technical and organisational security measures, including (where appropriate):
- access controls and authentication;
- encryption of data at rest and in transit;
- secure hosting environments located in the United Kingdom, with backups stored separately from the live Site;
- regular automated backups and the ability to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident;
- regular vulnerability scanning and patch management;
- incident detection and response procedures; and
- a process for regularly testing, assessing and evaluating the effectiveness of these measures, including penetration testing.
6.2 The Processor shall notify the Controller without undue delay and in any event within 24 hours of becoming aware of a Personal Data Breach or a reasonably suspected security incident (including near misses), using the contact routes in clause 16.
6.3 Such notification shall include all information reasonably required to enable the Controller to meet its regulatory obligations, including, so far as then known to the Processor: the nature of the Personal Data Breach or incident, including where possible the categories and approximate number of Data Subjects and of Personal Data records concerned; the likely consequences; the measures taken or proposed to be taken to address it, including where appropriate measures to mitigate its possible adverse effects; and a contact point where further information can be obtained. Notification shall not be delayed on the basis that an investigation is ongoing; where, and in so far as, it is not possible to provide all such information at the same time, the Processor shall provide it in phases without undue further delay.
6.4 The Processor shall not make any public statement regarding a Personal Data Breach without the Controller’s prior written consent unless required by law.
6.5 The Processor shall complete and publish an annual submission against the NHS Data Security and Protection Toolkit (or any successor assessment framework published by NHS England) by the annual publication deadline, achieving a status of Standards Met or better (or its equivalent under a successor framework), and shall notify the Controller without undue delay if it fails to achieve or ceases to hold that status.
6.6 The Processor shall maintain certification under the Cyber Essentials scheme, at Cyber Essentials or Cyber Essentials Plus level (or certification under any successor scheme backed by the National Cyber Security Centre), and shall notify the Controller without undue delay if that certification lapses.
6.7 The Processor shall provide to the Controller on request its current NHS Data Security and Protection Toolkit assessment status, its current Cyber Essentials certificate, stating its level and scope, and a summary of its backup and recovery arrangements.
7. Assistance to the Controller
7.1 Taking into account the nature of the Processing and the information available to it, the Processor shall provide reasonable assistance to the Controller to:
- respond to Data Subject rights requests;
- respond to complaints made by Data Subjects under section 164A of the Data Protection Act 2018, including any complaint passed to the Controller under clause 8;
- conduct Data Protection Impact Assessments (DPIAs) under Article 35 UK GDPR and any prior consultation with the Information Commissioner under Article 36 UK GDPR;
- comply with its obligations under Articles 32 to 36 UK GDPR, including the security of Processing and the notification of Personal Data Breaches to the Information Commissioner and, where required, to Data Subjects; and
- consult with supervisory authorities where required.
7.2 Assistance under this clause shall be provided to the extent reasonably possible and proportionate, and may be chargeable where it falls outside the scope of the Services.
8. Data Subject and Regulatory Requests
8.1 The Processor shall notify the Controller without undue delay, and in any event within five (5) Business Days, of receiving:
- any Data Subject request;
- any complaint relating to Personal Data; or
- any communication from a supervisory authority relating to the Processing.
8.2 The Processor shall not respond directly to any such request unless authorised in writing by the Controller or required by law.
9. Audits and Information Rights
9.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 UK GDPR and this Agreement, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, in accordance with Article 28(3)(h) UK GDPR.
9.2 Audits or inspections under clause 9.1 shall:
- be subject to reasonable prior notice;
- occur during Normal Business Hours;
- be limited to once per 12-month period, save that this limit shall not apply where an audit or inspection is required by a regulator or is reasonably required by the Controller in connection with a Personal Data Breach affecting Personal Data Processed under this Agreement;
- be conducted in a manner that minimises disruption to the Processor’s business; and
- where conducted by an auditor mandated by the Controller, be subject to that auditor first giving the Processor a written confidentiality undertaking on reasonable terms.
9.3 The Controller shall bear its own audit costs, and reimburse the Processor’s reasonable costs incurred in facilitating any audit.
9.4 The information made available under clause 9.1 may include the certification evidence described in clause 6.7. The parties acknowledge that, where reasonable, such evidence may be sufficient to demonstrate compliance without an audit or inspection under clause 9.2.
10. Freedom of Information and Transparency (Public Authorities)
10.1 Where the Controller is subject to the Freedom of Information Act 2000 or the Environmental Information Regulations 2004, the Processor shall provide reasonable assistance to enable compliance.
10.2 The Controller remains solely responsible for disclosure decisions.
11. Data Return and Deletion
11.1 Upon termination or expiry of the Services or of this Agreement, the Processor shall, at the Controller’s option, securely return to the Controller or delete all Personal Data, and shall delete existing copies, unless domestic law requires the Processor to store the Personal Data, in which case the Processor shall inform the Controller of that requirement, retain the Personal Data only for so long as that law requires and continue to protect it in accordance with this Agreement. Backup copies shall be deleted, and permanently removed, within the periods stated in Schedule 1 and remain subject to this Agreement until then.
11.2 The Controller shall exercise its option to have Personal Data returned by written request made before the Site is decommissioned under clause 10.6 of the Terms & Conditions of Supply, and the Processor shall return it by providing an export of the form submissions held on the Site. Where no such request has been made by then, the Controller shall be deemed to have elected deletion, and the Processor shall delete the Personal Data in accordance with clause 11.1 when the Site is decommissioned and confirm that it has done so on request.
11.3 Deletion shall be carried out in accordance with NHS and industry-recognised data destruction standards where applicable, as described in Schedule 2.
11.4 The Processor shall certify completion of return or deletion upon request.
11.5 The exit assistance provisions in clause 10.6 of the Terms & Conditions of Supply, the deletion of the Site and Customer Data after termination under that clause, and the decommissioning and deletion of development, staging or test environments under clause 3.5 of the Terms & Conditions of Supply, are subject to this clause 11 in respect of Personal Data.
12. Liability and Indemnity
12.1 The Processor shall indemnify the Controller against losses arising from the Processor’s breach of this Agreement or Data Protection Legislation, subject to the limitations of liability set out in clause 9.3 of the Terms & Conditions of Supply.
12.2 Nothing in this Agreement affects the rights of Data Subjects under Article 82 UK GDPR. Where either party has, in accordance with Article 82(4) UK GDPR, paid full compensation for damage suffered by a Data Subject, it may claim back from the other party the part of that compensation corresponding to the other party’s responsibility for the damage in accordance with Article 82(5) UK GDPR, and any such claim between the parties shall remain subject to the limitations of liability set out in clause 9.3 of the Terms & Conditions of Supply.
13. Termination
13.1 The Controller may terminate this Agreement with immediate effect by written notice where the Processor commits a material breach of this Agreement or where Processing poses a demonstrable risk to compliance with Data Protection Legislation.
13.2 A notice under clause 13.1 entitles the Controller to terminate, under clause 10.4 of the Terms & Conditions of Supply, those Services which cannot be provided without the Processing of Personal Data, by written notice with immediate effect. Clause 10.5 of the Terms & Conditions of Supply shall then apply subject to clause 11 of this Agreement, and clause 11 shall apply to the Personal Data concerned.
13.3 Following a notice under clause 13.1, the Processor shall Process Personal Data only to the extent necessary to return or delete it in accordance with clause 11, or as required by domestic law.
13.4 Clauses 11, 12 and 13 shall survive termination or expiry of this Agreement or of the Services, however arising.
14. Variation
14.1 Except as set out below, no variation to this Agreement shall be effective unless agreed in writing by both parties.
14.2 Notwithstanding clause 14.1, the Processor may update this Data Processing Agreement from time to time where such changes are required to:
- comply with applicable Data Protection Legislation or regulatory guidance;
- reflect changes in processing activities, security measures, or operational practices; or
- ensure ongoing alignment with the Processor’s Terms & Conditions of Supply.
14.3 Any updated version of this Data Processing Agreement shall be made available to the Controller and shall take effect in accordance with the change notification provisions set out in clause 13 of the Terms & Conditions of Supply.
14.4 Where an update materially reduces the level of data protection afforded to the Controller, the Controller may exercise any applicable termination rights set out in the Terms & Conditions of Supply.
15. Third Party Rights
15.1 This Agreement does not confer any rights on third parties under the Contracts (Rights of Third Parties) Act 1999. A Member Practice on whose behalf the Customer has contracted under clause 1.6 is a party to this Agreement in respect of its own Site and is not a third party for this purpose.
16. Contacts and Notices
16.1 The Processor’s data protection contact is its Data Protection Lead, Tree View Designs Ltd, 46 Skylark Lane, Whitfield, Dover, England, CT16 3QR. The Processor’s ICO registration number is ZA655395.
16.2 Notices and notifications under this Agreement, including under clauses 3.2, 4.2, 6, 8, 11 and 13, shall be given in writing by email (and may in addition be sent by post in accordance with clause 15.4 of the Terms & Conditions of Supply). Notices to the Processor shall be sent to enquiries@treeviewdesigns.co.uk, marked for the attention of the Data Protection Lead, or to such other email address as the Processor notifies to the Controller in writing from time to time. Operational support matters, including requests for assistance under clause 7, should be sent to the Processor’s helpdesk at support@treeviewdesigns.co.uk.
16.3 Notices to the Controller shall be sent to the data protection contact notified by the Controller to the Processor in writing or, where none has been notified, to the Designated Contact. The Controller shall keep its data protection contact details up to date.
16.4 A notice sent by email shall be deemed received at 9.00am on the next Business Day after transmission, provided no delivery failure is received, save that a notification under clause 6.2 shall take effect when sent. A Personal Data Breach notification under clause 6.2 shall in addition be made by telephone where practicable.
Schedule 1: Processing Details
- Subject matter
- The Personal Data submitted to, stored on, or generated by the Controller’s Site and the related digital services supplied by the Processor under the Contract.
- Controller(s)
- The Customer in respect of any Site provided for the Customer itself and, where clause 1.6 applies, each Member Practice in respect of the Personal Data Processed through its own Site.
- Nature of Processing
- Collection through online forms and SmartForms; storage and hosting on servers located in the United Kingdom; display to the Controller’s authorised users through the control panel and PatientInbox, and to Data Subjects through the PatientPortal; transmission of notifications and replies by email; automatic translation of Site content where a visitor requests it; indexing of Site content for site search; backup and restoration; access by the Processor’s authorised staff for technical support at the Controller’s request and, where the Controller has purchased Premium Support or an Add-on Service, content and form administration on the Controller’s instructions (including, where the Customer has Group Central Management, publication of content to connected Sites on the instructions of the Customer’s authorised administrators); and deletion. The Processor makes no decisions about Data Subjects, automated or otherwise, on the basis of the Personal Data; all review, triage and responses to submissions are carried out by the Controller’s authorised staff.
- Purpose
- Delivery, hosting, and support of patient-facing healthcare websites, forms, and related digital services.
- Duration
- As set out in clause 2.1: the term of the Contract and thereafter until all Personal Data has been returned or deleted in accordance with clause 11.
- Retention
- Retention is controlled by the Controller through the retention period set for each form. Submissions received through forms, including SmartForms, are deleted from the platform automatically once that period has passed since the submission was closed. The default retention period is 120 days. The Controller’s authorised administrators can increase or reduce it in the control panel, and the Processor will change it on the Controller’s written instruction, which is a documented instruction under clause 3.1. Automatic deletion takes place without further notice, and the Processor does not restore deleted submissions. The Controller is responsible for setting a retention period that meets its own records management obligations, and for exporting or recording elsewhere any submission that it needs to keep for longer. Backup copies are taken daily, stored separately from the live Site and currently retained for seven (7) days, after which the oldest copy is replaced by the newest. A replaced or deleted copy remains recoverable by the Processor for up to a further seven (7) days and is then permanently removed. Personal Data deleted from the platform, including a form submission deleted at the end of its retention period and any files attached to it, may therefore remain in backup copies for up to fourteen (14) days. Where a Site is decommissioned under clause 11, the Processor deletes the backup copies of that Site at the same time, and they are permanently removed within seven (7) days.
- Categories of Data Subjects
- Patients, carers, service users, website visitors, and the Controller’s staff and authorised users.
- Categories of Personal Data
-
- identifying and contact details;
- health and care-related information submitted via forms, including SmartForms;
- free-text communications, including submissions, replies and PatientPortal messages;
- control panel user account details and audit trail records of actions taken by the Controller’s authorised users;
- website usage, search and feedback data, including where the Controller enables PatientInsights;
- translation requests made by visitors using the automatic translation feature;
- email notification metadata, including recipient addresses and delivery records; and
- operational metadata.
- Special Category Data
- Yes. The Personal Data includes data concerning health within Article 9(1) UK GDPR submitted by or about Data Subjects through forms, including SmartForms.
- Obligations and rights of the Controller
- As set out in this Agreement (including clauses 3.3 and 3.5) and in clause 8 of the Terms & Conditions of Supply.
- Lawful basis and Article 9 condition
- Determined and documented by the Controller under Article 6 UK GDPR and, for Special Category Data, under Article 9 UK GDPR and Schedule 1 to the Data Protection Act 2018. For the provision of patient care this is commonly Article 9(2)(h) UK GDPR together with paragraph 2 of Part 1 of Schedule 1 to the Data Protection Act 2018. The Processor makes no determination of the lawful basis or condition for the Processing.
Schedule 2: Data Destruction Standards
Personal Data shall be securely destroyed or overwritten in accordance with applicable NHS England guidance, UK GDPR requirements, and recognised industry standards. Certification shall be provided upon request.
Schedule 3: Sub-processor Categories and Locations
This Schedule sets out the categories of Sub-processor the Controller authorises under clause 4.1, the purpose for which each category is engaged, the permitted location of Processing and the transfer mechanism relied on. The current named list of Sub-processors in each category is provided to the Controller at contract signature and on request, and changes are notified under clause 4.2 with the objection and termination rights set out there. Where this Schedule or the current named list states a location outside the United Kingdom, the Restricted Transfer is made only under clause 5.
| Category | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hosting and infrastructure | Hosting of the Site, the Customer Data and form submissions, including the Digital Triage Features | United Kingdom | None required (no Restricted Transfer) |
| Backup | Backup and restoration of the Site and its data, stored separately from the live Site | United Kingdom | None required (no Restricted Transfer) |
| Email delivery | Transmission of notification emails and replies generated by the Site, including notifications from the Digital Triage Features and Group Central Management | As stated in the current named list; outside the United Kingdom only under clause 5 | As stated in the current named list: adequacy regulations under Article 45A UK GDPR or appropriate safeguards under Article 46 UK GDPR |
| Analytics (Google Analytics 4) | Usage statistics for the Site, collected only with visitors’ consent, which the Controller can access on request and, where the Controller has PatientInsights, through its reports | As stated in the current named list; outside the United Kingdom only under clause 5 | As stated in the current named list: adequacy regulations under Article 45A UK GDPR or appropriate safeguards under Article 46 UK GDPR |
| Automatic translation (Google Translate) | Automatic translation of Site content where a visitor requests it | As stated in the current named list; outside the United Kingdom only under clause 5 | As stated in the current named list: adequacy regulations under Article 45A UK GDPR or appropriate safeguards under Article 46 UK GDPR |
| Security, monitoring and support tooling | Security scanning, monitoring, incident detection and support tooling used to operate the Services | As stated in the current named list; outside the United Kingdom only under clause 5 | As stated in the current named list: adequacy regulations under Article 45A UK GDPR or appropriate safeguards under Article 46 UK GDPR |
The Site’s search function uses a third-party search service (currently Algolia) under an account that the Controller holds directly with that provider. That provider is engaged by the Controller in accordance with clause 4.7 and is therefore not listed above.
Version history
- 2.0, effective 18 September 2026
- Corrects the Processor’s registered particulars and identifies the Controller as the Customer named in the Order, with a new clause 1.6 for Member Practices. Adds a definitions clause, Controller obligations (clause 3.3), confidentiality and Caldicott commitments (clause 3.4) and a statement of the Processor’s own controller processing (clause 2.4). Restates the Sub-processor process with thirty days’ notice, an objection right and a new Schedule 3. Rewrites clause 5 in UK GDPR terms with a United Kingdom hosting commitment. Expands the security measures, defines the content of breach notifications with phased reporting, and adds the NHS Data Security and Protection Toolkit and Cyber Essentials commitments. Confirms that analytics runs only with visitors’ consent and that third-party services chosen by the Controller are not Sub-processors (clauses 4.4 and 4.7). Records the automatic deletion of form submissions at the end of their retention period (120 days by default), treats the search provider as engaged by the Controller under its own account, and requires any request for the return of Personal Data to be made before the Site is decommissioned (Schedule 1, Schedule 3 and clause 11.2). Names Articles 32 to 36 in the assistance clause, tightens the notification and audit provisions, and completes the return and deletion clause. Adds the Article 82 confirmation, the effect of termination on the Contract, and a contacts and notices clause. Restructures Schedule 1 as a processing record with retention, Special Category Data and lawful basis entries, and updates the NHS body references following the merger of the former national digital body into NHS England.
- 1.1, effective 1 February 2026
- Previous version.
Earlier versions continue to govern a Controller until the updated Agreement takes effect under clause 14.