Data Processing Agreement

Pulse Health Ltd — UK GDPR · Version 1.3

Last updated: August 2026 · Document version 1.3

1. Parties

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

  • Data Controller ("Controller"): The clinic or healthcare practice subscribing to Pulse PMS ("you", "Subscriber")
  • Data Processor ("Processor"): Pulse Health Ltd ("we", "us", "Pulse Health")

This DPA is entered into pursuant to Article 28 of the UK General Data Protection Regulation (UK GDPR) and supplements our Terms of Service.

2. Subject Matter & Duration

2.1. Subject matter: The Processor processes personal data on behalf of the Controller to provide the Pulse PMS practice management service.

2.2. Duration: This DPA remains in effect for the duration of the Controller's subscription and for 90 days thereafter (the data export/deletion period).

2.3. Nature of processing: Collection, storage, organisation, retrieval, consultation, use, disclosure by transmission, and erasure of personal data in connection with healthcare practice management.

3. Categories of Data Subjects

  • Patients of the Controller's healthcare practice
  • Authorised Users (staff members) of the Controller
  • Referring practitioners and external contacts

4. Types of Personal Data Processed

  • Patient identity data: Name, date of birth, NHS number, gender, title
  • Patient contact data: Address, phone, email, emergency contacts
  • Special category data (health): Medical history, clinical notes, treatment records, SOAP notes, diagnoses, prescriptions, exercise programmes
  • Financial data: Invoice records, payment history (card details are processed by Stripe as an independent controller and are not stored by Pulse Health)
  • Communication data: SMS/email/WhatsApp message logs, appointment reminders
  • Staff data: Names, email addresses, roles, login activity

5. Processor Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller, unless required by law
  • Ensure that all personnel authorised to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures (see Section 7)
  • Not engage a sub-processor without prior written authorisation from the Controller (see Section 8)
  • Assist the Controller with data subject access requests and other GDPR rights
  • Assist the Controller with data protection impact assessments where applicable
  • Notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach
  • Upon termination, delete or return all personal data as instructed by the Controller, and certify deletion
  • Make available all information necessary to demonstrate compliance with this DPA and allow for audits

5.1. Documented instructions for service operations: The Controller instructs the Processor to access personal data as reasonably necessary to host, maintain, secure, and support the Service, including diagnosing and remedying errors, defects, and incidents. Such access is limited to authorised Processor personnel subject to confidentiality and least-privilege controls.

5.2. Minimum necessary scope: The Processor shall restrict access to the categories of data and records reasonably required for the specific support, maintenance, or remediation task. By way of example, where an issue relates to appointments or scheduling, the Processor shall not review clinical treatment notes or invoice/payment records unless those areas are directly relevant to resolving the reported issue.

5.3. No third-party disclosure for support: Personal data accessed for support or remediation shall not be disclosed to third parties except where required by law or where a sub-processor is engaged under Section 8 to provide hosting or operational services, in each case subject to equivalent data protection obligations.

6. Controller Obligations

The Controller shall:

  • Ensure it has a valid lawful basis for all personal data processed through the Service
  • Provide patients with appropriate privacy notices
  • Obtain necessary consents where required (e.g., for marketing communications)
  • Ensure Authorised Users are properly trained on data protection and use the Service in compliance with applicable laws
  • Promptly notify the Processor of any changes to processing instructions

7. Security Measures

The Processor implements the following technical and organisational measures:

Technical Measures

  • Encryption in transit: All data transmitted via TLS 1.2+ (HTTPS)
  • Encryption at rest: AES-256 encryption on all databases and storage
  • Access controls: Role-based access control (RBAC) with five distinct role levels
  • Authentication: Password hashing (bcrypt), session management with JWT tokens
  • Audit logging: Comprehensive audit trail of data access and modifications
  • Data isolation: Clinic data is logically separated using unique clinic identifiers
  • Infrastructure: Hosted on AWS eu-west-2 (London) with redundancy and automated backups

Organisational Measures

  • Staff confidentiality agreements and data protection training
  • Incident response procedures with defined escalation paths
  • Regular security reviews and vulnerability assessments
  • Principle of least privilege for internal access

8. Sub-Processors

8.1. The Controller provides general written authorisation for the Processor to engage sub-processors, subject to the conditions in this section.

8.2. The Processor shall inform the Controller of any intended changes to sub-processors, giving 30 days to object.

8.3. The Processor shall ensure all sub-processors are bound by data protection obligations no less protective than those in this DPA.

Current authorised sub-processors:

Sub-ProcessorPurposeData Location
Amazon Web Services (AWS)Cloud hosting, email (SES), SMS (SNS)UK (eu-west-2)
MongoDB AtlasDatabase hostingUK / EU
StripePayment processingEU (Ireland)
TwilioSMS & WhatsApp messagingEU / US (with SCCs)
Google (OAuth)Patient authenticationEU / US (with SCCs)
OpenAIAI features (clinical scribe, assistant)US (with SCCs & DPA)

9. International Transfers

9.1. The Processor stores primary data in UK data centres (AWS eu-west-2, London).

9.2. Where sub-processors transfer data outside the UK, appropriate safeguards are in place including Standard Contractual Clauses (SCCs) as approved by the ICO, or the sub-processor's country has received a UK adequacy decision.

9.3. The Processor shall inform the Controller of any new international transfer and the safeguards in place.

10. Data Breach Notification

10.1. The Processor shall notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach.

10.2. The notification shall include:

  • Description of the nature of the breach, including categories and approximate number of data subjects affected
  • Name and contact details of the data protection point of contact
  • Description of likely consequences
  • Description of measures taken or proposed to address the breach

10.3. The Processor shall cooperate with the Controller and take reasonable steps to mitigate the effects of any breach.

11. Data Subject Rights

11.1. The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timescales required by UK GDPR.

11.2. The Service provides built-in tools for the Controller to fulfil these requests, including data export (JSON/CSV), patient record access, and data deletion functionality.

12. Audit Rights

12.1. The Controller has the right to audit the Processor's compliance with this DPA, with reasonable notice and during normal business hours.

12.2. The Processor shall make available relevant compliance documentation, security certifications, and audit reports upon request.

13. Data Retention & Deletion

13.1. The Processor retains personal data for the duration of the Controller's subscription.

13.2. Upon termination or expiry of the subscription, the Controller has 90 days to export data.

13.3. After the 90-day export period, the Processor shall securely delete all personal data and provide written confirmation of deletion upon request.

13.4. Backup copies will be purged within 30 days of the deletion date.

14. Liability & Relationship to Terms

14.1. The Processor's obligations under this DPA do not expand the liability caps, exclusions, or indemnities in the Terms of Service. Any claim arising from processing under this DPA is subject to those Terms, including limitations relating to data loss, cyber-attack, and hosting failure, except where liability cannot be limited by law.

14.2. The Controller remains responsible for instructions that comply with UK GDPR and for maintaining appropriate copies of clinical records outside the Service where required by professional standards.

14.3. Appropriate technical and organisational measures reduce but do not eliminate the risk of personal data breach. Notification duties under Section 10 apply if a breach occurs; they do not create uncapped liability beyond the Terms.

15. Governing Law

This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.

16. Contact

For questions about this DPA:

Pulse Health Ltd
Company number: 17122797
Registered office: 3 Beacon House, Kempson Way, Bury St. Edmunds, Suffolk, IP32 7AR
Data Protection Contact
Email: contact@pulsehealth.uk