← AutomateFlow

Data Processing Agreement

Between E.A.E Enterprise Ltd t/a AutomateFlow (the "Processor", Company No. 16890393) and the dental practice named below (the "Controller"). Forms part of the AutomateFlow service agreement. Governed by the laws of England and Wales.

This Agreement sets out the terms on which the Processor processes personal data on behalf of the Controller, in accordance with Article 28 of the UK GDPR.

1. Subject matter and duration

The Processor provides an AI reception and booking service. It processes personal data for as long as the Controller's account is active, and afterwards only as set out in clause 8.

2. Nature and purpose of processing

Receiving and recording patient enquiries; booking, rescheduling and cancelling appointments; sending confirmations, reminders and recalls; taking deposits; and alerting the Controller's team. Processing is limited to what is necessary for these purposes.

3. Types of personal data and data subjects

Data subjectsPersonal data
The Controller's patients and prospective patients; the Controller's staff users.Name, phone, email, appointment details, and the content patients choose to enter into the assistant. This may incidentally include special category (health) data under Article 9 where a patient discloses it; the service is designed to minimise this by deflecting clinical questions to the Controller's team.

4. The Processor's obligations

  1. Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law.
  2. Ensure persons authorised to process the data are bound by confidentiality.
  3. Implement appropriate technical and organisational security measures (clause 6).
  4. Respect the conditions for engaging sub-processors (clause 5).
  5. Taking into account the nature of processing, assist the Controller with responding to data-subject requests and rights.
  6. Assist the Controller with security, breach notification, data protection impact assessments and prior consultation.
  7. Notify the Controller without undue delay (and within 72 hours) on becoming aware of a personal data breach affecting the Controller's data.
  8. Make available information needed to demonstrate compliance and allow for and contribute to audits by the Controller or its appointed auditor, on reasonable notice.

5. Sub-processors

The Controller authorises the use of the sub-processors below. The Processor imposes data-protection terms on each that are no less protective than this Agreement, and remains liable for their performance. The Processor will give notice of any intended change, allowing the Controller to object.

Sub-processorServiceLocation
Google Cloud / FirebaseDatabase and hostingEU/UK region where available
Google (Gemini API)Generating assistant replies; not used to train models under the paid API termsGoogle data centres
StripePaymentsUK/EU/US (adequacy / IDTA safeguards)
TwilioSMS (optional)UK/EU/US (IDTA safeguards)
Email delivery providerTransactional emailUK/EU

6. Security measures

Encryption of data in transit; access restricted to authenticated users; per-practice access tokens for private dashboards; segregation of practice data; least-privilege access; and regular review of access and patching.

7. International transfers

Where personal data is transferred outside the UK, the Processor ensures an appropriate safeguard is in place, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or transfer to a country with UK adequacy.

8. Return and deletion

On termination, the Processor will, at the Controller's choice, delete or return all personal data and delete existing copies within 30 days, unless UK law requires storage.

9. General

This Agreement prevails over any conflicting term in the service agreement in respect of data processing. If any provision is found invalid, the remainder continues in force.

Controller (the practice)
Name / signature / date
Processor (AutomateFlow / E.A.E Enterprise Ltd)
Name / signature / date