Pulse Health Ltd — UK GDPR · Version 1.3
Last updated: August 2026 · Document version 1.3
This Data Processing Agreement ("DPA") forms part of the Terms of Service between:
This DPA is entered into pursuant to Article 28 of the UK General Data Protection Regulation (UK GDPR) and supplements our Terms of Service.
2.1. Subject matter: The Processor processes personal data on behalf of the Controller to provide the Pulse PMS practice management service.
2.2. Duration: This DPA remains in effect for the duration of the Controller's subscription and for 90 days thereafter (the data export/deletion period).
2.3. Nature of processing: Collection, storage, organisation, retrieval, consultation, use, disclosure by transmission, and erasure of personal data in connection with healthcare practice management.
The Processor shall:
5.1. Documented instructions for service operations: The Controller instructs the Processor to access personal data as reasonably necessary to host, maintain, secure, and support the Service, including diagnosing and remedying errors, defects, and incidents. Such access is limited to authorised Processor personnel subject to confidentiality and least-privilege controls.
5.2. Minimum necessary scope: The Processor shall restrict access to the categories of data and records reasonably required for the specific support, maintenance, or remediation task. By way of example, where an issue relates to appointments or scheduling, the Processor shall not review clinical treatment notes or invoice/payment records unless those areas are directly relevant to resolving the reported issue.
5.3. No third-party disclosure for support: Personal data accessed for support or remediation shall not be disclosed to third parties except where required by law or where a sub-processor is engaged under Section 8 to provide hosting or operational services, in each case subject to equivalent data protection obligations.
The Controller shall:
The Processor implements the following technical and organisational measures:
8.1. The Controller provides general written authorisation for the Processor to engage sub-processors, subject to the conditions in this section.
8.2. The Processor shall inform the Controller of any intended changes to sub-processors, giving 30 days to object.
8.3. The Processor shall ensure all sub-processors are bound by data protection obligations no less protective than those in this DPA.
Current authorised sub-processors:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, email (SES), SMS (SNS) | UK (eu-west-2) |
| MongoDB Atlas | Database hosting | UK / EU |
| Stripe | Payment processing | EU (Ireland) |
| Twilio | SMS & WhatsApp messaging | EU / US (with SCCs) |
| Google (OAuth) | Patient authentication | EU / US (with SCCs) |
| OpenAI | AI features (clinical scribe, assistant) | US (with SCCs & DPA) |
9.1. The Processor stores primary data in UK data centres (AWS eu-west-2, London).
9.2. Where sub-processors transfer data outside the UK, appropriate safeguards are in place including Standard Contractual Clauses (SCCs) as approved by the ICO, or the sub-processor's country has received a UK adequacy decision.
9.3. The Processor shall inform the Controller of any new international transfer and the safeguards in place.
10.1. The Processor shall notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach.
10.2. The notification shall include:
10.3. The Processor shall cooperate with the Controller and take reasonable steps to mitigate the effects of any breach.
11.1. The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timescales required by UK GDPR.
11.2. The Service provides built-in tools for the Controller to fulfil these requests, including data export (JSON/CSV), patient record access, and data deletion functionality.
12.1. The Controller has the right to audit the Processor's compliance with this DPA, with reasonable notice and during normal business hours.
12.2. The Processor shall make available relevant compliance documentation, security certifications, and audit reports upon request.
13.1. The Processor retains personal data for the duration of the Controller's subscription.
13.2. Upon termination or expiry of the subscription, the Controller has 90 days to export data.
13.3. After the 90-day export period, the Processor shall securely delete all personal data and provide written confirmation of deletion upon request.
13.4. Backup copies will be purged within 30 days of the deletion date.
14.1. The Processor's obligations under this DPA do not expand the liability caps, exclusions, or indemnities in the Terms of Service. Any claim arising from processing under this DPA is subject to those Terms, including limitations relating to data loss, cyber-attack, and hosting failure, except where liability cannot be limited by law.
14.2. The Controller remains responsible for instructions that comply with UK GDPR and for maintaining appropriate copies of clinical records outside the Service where required by professional standards.
14.3. Appropriate technical and organisational measures reduce but do not eliminate the risk of personal data breach. Notification duties under Section 10 apply if a breach occurs; they do not create uncapped liability beyond the Terms.
This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.
For questions about this DPA:
Pulse Health Ltd
Company number: 17122797
Registered office: 3 Beacon House, Kempson Way, Bury St. Edmunds, Suffolk, IP32 7AR
Data Protection Contact
Email: contact@pulsehealth.uk