This Agreement sets out the terms on which the Processor processes personal data on behalf of the Controller, in accordance with Article 28 of the UK GDPR.
The Processor provides an AI reception and booking service. It processes personal data for as long as the Controller's account is active, and afterwards only as set out in clause 8.
Receiving and recording patient enquiries; booking, rescheduling and cancelling appointments; sending confirmations, reminders and recalls; taking deposits; and alerting the Controller's team. Processing is limited to what is necessary for these purposes.
| Data subjects | Personal data |
|---|---|
| The Controller's patients and prospective patients; the Controller's staff users. | Name, phone, email, appointment details, and the content patients choose to enter into the assistant. This may incidentally include special category (health) data under Article 9 where a patient discloses it; the service is designed to minimise this by deflecting clinical questions to the Controller's team. |
The Controller authorises the use of the sub-processors below. The Processor imposes data-protection terms on each that are no less protective than this Agreement, and remains liable for their performance. The Processor will give notice of any intended change, allowing the Controller to object.
| Sub-processor | Service | Location |
|---|---|---|
| Google Cloud / Firebase | Database and hosting | EU/UK region where available |
| Google (Gemini API) | Generating assistant replies; not used to train models under the paid API terms | Google data centres |
| Stripe | Payments | UK/EU/US (adequacy / IDTA safeguards) |
| Twilio | SMS (optional) | UK/EU/US (IDTA safeguards) |
| Email delivery provider | Transactional email | UK/EU |
Encryption of data in transit; access restricted to authenticated users; per-practice access tokens for private dashboards; segregation of practice data; least-privilege access; and regular review of access and patching.
Where personal data is transferred outside the UK, the Processor ensures an appropriate safeguard is in place, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or transfer to a country with UK adequacy.
On termination, the Processor will, at the Controller's choice, delete or return all personal data and delete existing copies within 30 days, unless UK law requires storage.
This Agreement prevails over any conflicting term in the service agreement in respect of data processing. If any provision is found invalid, the remainder continues in force.