Legal
Data processing agreement
This is the Article 28 agreement that governs how Clinicify processes patient data on a clinic's behalf. It forms part of the terms of service, so you do not need to sign it separately.
Last updated: 6 August 2026
1. What this document is
The UK GDPR says that when one organisation processes personal data on another's behalf, there has to be a written contract covering specific things. Article 28 lists them. This document is that contract.
It forms part of our terms of service. If you have accepted those, you have this too, and there is nothing extra to sign. If your own governance process needs a countersigned copy, email [email protected] and we will sort it out.
In this document, "you" is the clinic and "we" is Clinicify, operated by CLINICIFY LTD (company number 17386702, registered office 16 Mansfield Road, Poole, BH14 0DF, UK).
2. Roles: you are the controller, we are the processor
For patient data, you are the controller and we are the processor. You decide what is recorded, why, and for how long. We act on your instructions.
For your staff accounts, billing and how your clinic uses the product, we are the controller, and this document does not govern that. Our privacy policy does.
Neither of us is a joint controller with the other for patient data. If a regulator ever disagreed with that characterisation, we would both cooperate to fix the paperwork rather than argue about it.
3. Subject matter, duration, nature and purpose
- Subject matter
- Processing the personal data in your Clinicify account so that we can provide the service to you.
- Duration
- For as long as your subscription runs, plus the 90 days and the deletion timescales in section 13.
- Nature of the processing
- Storing, organising, retrieving, displaying, transmitting, backing up, and deleting data. Sending appointment emails and text messages to your patients. Creating calendar and video-consultation entries where you have connected those integrations. Drafting text for a clinician to review where you use the question-and-answer feature.
- Purpose
- Practice management: appointments, patient records, lab results, payments, patient communication, and CQC compliance evidence. We process patient data for no purpose of our own.
4. What data, and whose
Categories of data subject:
- Your patients, including prospective patients who begin a booking
- Your staff, where their details appear in patient records, for example as the treating clinician
Types of personal data:
- Identity and contact details: name, date of birth, address, email address, phone number
- Appointment data: bookings, history, attendance, cancellations
- Clinical records: notes, treatment records, prescriptions and medication records
- Lab results
- Consent records
- Photographs, where your clinic records them
- Payment records, excluding card numbers, which go directly to Stripe
- Messages between your clinic and the patient
Special category data. Most of the above is health data, which is special category data under Article 9. We process it on the basis that you have established the appropriate Article 9 condition, which for a clinic providing healthcare is normally Article 9(2)(h).
Children. If your clinic treats patients under 18, their data is in scope on the same basis. You are responsible for handling consent and parental responsibility correctly.
5. What we commit to
- Process only on your instructions. We process patient data only to provide the service and only as you instruct, including through the settings you choose in the app. We do not process it for our own purposes.
- Tell you if an instruction looks unlawful. If we think an instruction breaches data protection law, we will tell you rather than quietly carry it out.
- Tell you if the law forces our hand. If we are ever legally required to process your data in a way you have not instructed, we will tell you before we do it, unless the law forbids us from telling you.
- Confidentiality. Everyone we let near patient data is bound by a duty of confidence. Access is limited to the people who need it to do their job.
- Never sell it, never train on it. We do not sell patient data and we do not use it to train or improve AI or machine-learning models, ours or anyone else's.
- Security. The measures in section 8.
- Help with your own duties. Data subject requests (section 9), breaches (section 10), and, where you need it, data protection impact assessments and prior consultation with the ICO.
- Delete or return the data when we are done (section 13).
- Let you check. Audit and information rights are in section 12.
6. What you commit to
- That you have a lawful basis and the right Article 9 condition for the patient data you put into Clinicify.
- That you have told your patients how their data is used, in your own privacy notice. Ours does not do that job for you: we are your processor, not their controller.
- That your instructions to us, including the settings you choose, comply with data protection law.
- That you manage access inside your clinic responsibly: your own staff accounts, roles, and offboarding people who leave.
- That you keep whatever clinical records your professional and regulatory duties require, including after you stop using Clinicify.
7. Sub-processors, and your right to object
You give us general authorisation to use sub-processors for the parts of the service that need them. The current list, with what each one does and where it is, is in our privacy policy. That list is part of this agreement.
Our commitments on sub-processors:
- Each one is bound by a written contract imposing data protection obligations no weaker than the ones in this agreement.
- Each one gets only the data it needs for its function. Some, such as Xero, Google and Zoom, only receive anything at all if you connect that integration.
- We remain responsible to you for what our sub-processors do with your data. If one of them fails to meet its obligations, that is our problem to answer for, not yours to chase.
Changes and your right to object. We will give you at least 30 days' notice, by email to the account holder, before we add a new sub-processor or replace an existing one. If you have a reasonable data protection objection, tell us within those 30 days and we will work with you to find a way round it. If we cannot, you may end the affected part of the service, or the contract, without penalty, and we will refund the unused part of anything you have paid in advance.
8. Security measures
These are the technical and organisational measures we have in place, as required by Article 32.
- Encryption in transit. All traffic over TLS. There is no unencrypted route into the service.
- Encryption at rest for stored data.
- Per-clinic encryption keys for patient data, so one clinic's records are not protected by the same key as another's.
- Integration tokens for Google and Zoom encrypted with AES-256-GCM, with the key held as a platform secret separate from the database.
- Role-based access control within a clinic. Clinicians, receptionists and administrators get different views.
- Audit logging of access to patient records, so you can see who looked at what.
- Multi-factor authentication available on staff accounts, provided through our authentication sub-processor.
- Separation between clinics, so one clinic cannot reach another's data.
- Encrypted backups.
- Least-privilege internal access. Access to production data is limited to the people who need it to run the service.
Security is not a fixed list. We may change a measure for one that is at least as protective, and we will not weaken the overall level of protection.
9. Helping you answer patient requests
Patients exercise their rights against you, because you are the controller. Most of what you need is in the app already: you can find, correct, export and delete a patient record yourself, without asking us.
If a request needs something the app cannot do, email [email protected] and we will help within a timescale that lets you meet your one-month deadline.
If a patient contacts us directly about data we hold for you, we will not answer on your behalf. We will pass the request to you and tell the patient we have done so.
10. Breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data.
We will tell you, as far as we know it at the time:
- what happened and when
- which categories of data and roughly how many people are affected
- the likely consequences
- what we are doing about it, and what we suggest you do
- a contact who can answer your follow-up questions
We will keep you updated as we learn more, and we will help you make any notification you owe to the ICO or to your patients. You have your own 72-hour duty to the ICO and you cannot meet it if we are slow, so this is a hard commitment rather than a target.
We will not notify the ICO or your patients on your behalf unless you ask us to in writing, because that is the controller's call.
11. International transfers
Patient data is held in the UK and the EU. We will not transfer patient data outside the UK without a lawful transfer mechanism in place: UK adequacy regulations where they apply, and otherwise the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment on file.
The Google Analytics transfer to the United States described in our privacy policy relates to visitors to our marketing website only. Analytics does not run inside the staff app or the patient portal, so no patient data is involved in it.
12. Audit and information rights
You are entitled to satisfy yourself that we are doing what this agreement says. In practice:
- Ask us questions and we will answer them, including completing a reasonable security or supplier assurance questionnaire.
- We will give you the information you need to demonstrate compliance to your own auditors or to the ICO.
- You may audit us, or appoint an independent auditor to do it, no more than once a year unless a breach or a regulator's instruction makes another one necessary. Give us reasonable notice, keep it proportionate, and do not disrupt other customers or see their data.
- You cover your own costs of an audit. We cover ours, unless the audit finds a material failure on our side, in which case we cover both.
13. Deletion or return when we finish
When the contract ends, you choose: we return your data, we delete it, or both. In practice most clinics export and then ask us to delete.
- You can export at any time while the subscription is active, and throughout the 90 days after it ends. Export download links expire after 7 days. What the export contains is set out in our terms of service.
- The 90 days is one rule for everyone, whether a paid subscription was cancelled or a free trial finished without one. Your clinic and its data are kept for 90 days, then permanently deleted, with warning emails 14 days and 3 days before the deletion date. Subscribing again during those 90 days stops the deletion.
- After the 90 days, we delete your data, including from our sub-processors, in line with the retention periods in our privacy policy.
- Backups. Deleted database records can persist in encrypted backups for up to 6 hours before those backups expire, without any further action from you. Uploaded files, such as lab reports and photographs, are held in object storage with no versioning, so they are deleted immediately and are not in any backup. Neither is restored to the live service.
- We may keep data where the law requires it, for example billing records for 6 years. Where we do, we keep only what the law requires and we keep processing it under this agreement.
We will confirm in writing when deletion is done, if you ask us to.
14. Liability and precedence
The liability provisions in our terms of service apply to this agreement too. Nothing here limits either of our obligations or liabilities under the UK GDPR itself, which are what they are regardless of what a contract says.
If this agreement and the terms of service conflict on anything about the processing of personal data, this agreement wins. On everything else, the terms of service win. See which document wins.
The obligations in this agreement on confidentiality, security, deletion and breach notification continue after the contract ends, for as long as we hold any of your data.
15. Contact
Anything about this agreement, or about data protection generally: [email protected]
Post: 16 Mansfield Road, Poole, BH14 0DF, UK
See also our privacy policy and terms of service.