Data Processing Agreement

Version 1.0 · Effective 12 June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between you and us for your use of CareCompetent (the “Agreement”). It sets out the terms on which we process personal data on your behalf under Article 28 of the UK GDPR.

Controller and processor

For the personal data you upload into the Service (your staff records, assessments, evidence, uploaded policies and related data — the Customer Personal Data”), you are the controller and we are your processor. You decide why and how that data is processed; we process it only to provide the Service and on your instructions.

1. Definitions

Terms such as “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “special categories of personal data” have the meanings given in UK Data Protection Law. “UK Data Protection Law” means the UK GDPR and the Data Protection Act 2018, and any other data-protection laws applicable to us in the UK. “Sub-processor” means any third party we engage to process Customer Personal Data.

2. Subject matter and details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. We process Customer Personal Data for the duration of the Agreement and for any period afterwards during which we are required to retain it under the Agreement or by law.

3. Our obligations as processor

We will:

  • process Customer Personal Data only on your documented instructions (including those in the Agreement and as given through your use of the Service), unless required to do otherwise by law, in which case we will inform you first unless the law prohibits it;
  • ensure that people authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality;
  • implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2 (Article 32);
  • respect the conditions in clauses 4 and 5 for engaging sub-processors;
  • taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights;
  • assist you in ensuring compliance with your obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to us;
  • notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and provide reasonable information to help you meet your own breach-reporting obligations within your 72-hour deadline;
  • at your choice, delete or return all Customer Personal Data to you after the end of the provision of the Service, and delete existing copies unless we are required by law to keep them; we will complete deletion within 30 days after the end of the read-only export window described in the Agreement, subject to any legal retention requirement and routine backup cycles, and will confirm deletion to you on request; and
  • make available to you the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in clause 6.

Your documented instructions include our processing of Customer Personal Data to provide, secure, maintain and improve the Service, and our creation and use of aggregated and anonymised data (which does not identify any individual) for those purposes. If, in our opinion, an instruction infringes UK Data Protection Law, we will inform you (though we are not obliged to give you legal advice).

4. Sub-processors

You give us general authorisation to engage sub-processors to process Customer Personal Data. Our current sub-processors are listed in Annex 3. We will impose data-protection obligations on each sub-processor that are substantially equivalent to those in this DPA, and we remain responsible to you for each sub-processor’s performance.

We will give you at least 30 days’ notice before a new or replacement sub-processor begins processing Customer Personal Data (for example by updating Annex 3 or by email). If you have a reasonable, data-protection-related objection, you may raise it with us within that period and we will work with you in good faith; if we cannot resolve it, your remedy is to stop using the affected part of the Service and, if necessary, to terminate the Agreement without penalty for the unused, pre-paid remainder of your then-current term.

5. International transfers

We and our sub-processors may transfer Customer Personal Data outside the UK. Where we do, we will ensure an appropriate safeguard recognised under UK Data Protection Law is in place — such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — so that the data remains protected to UK standards.

6. Records and audit

We will maintain records of our processing of Customer Personal Data as required by Article 30. On reasonable prior written notice, and no more than once a year (unless required by a supervisory authority or following a personal data breach), we will make available information reasonably necessary to demonstrate our compliance with this DPA, and allow you (or an independent auditor you appoint, who is bound by confidentiality) to verify that compliance. Audits must be conducted during business hours, without unreasonable disruption, and subject to confidentiality.

7. Your obligations as controller

You warrant and undertake that:

  • you have a lawful basis (and, for special-category data, an Article 9 condition) for the processing of Customer Personal Data through the Service;
  • you have provided all required privacy information to, and where necessary obtained any required consents from, the relevant data subjects;
  • your instructions to us for processing Customer Personal Data comply with UK Data Protection Law; and
  • you are responsible for the accuracy, quality and legality of Customer Personal Data and the means by which you acquired it.

Where you choose to include special-category data (such as health- related information) in Customer Personal Data — including data processed by the AI features — you are responsible for ensuring you have an appropriate Article 9 condition for that processing, and for carrying out any data protection impact assessment that may be required under Article 35 of the UK GDPR. We will provide reasonable assistance as described in clause 3.

8. Liability and precedence

Each party’s liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. If there is any conflict between this DPA and the rest of the Agreement on the subject of the processing of personal data, this DPA prevails.

9. Annex 1 — Details of processing

  • Subject matter: our provision of the CareCompetent Service to you.
  • Duration: the term of the Agreement, plus any retention period permitted or required by the Agreement or law.
  • Nature and purpose: hosting, storage, organisation, structuring, retrieval, analysis, generation of reports and outputs (including using AI), and other processing necessary to provide the competency-management and governance features of the Service.
  • Types of personal data: staff identity and contact details; role, employment and training information; competency assessments, observations, evidence (which may include photographs) and assessor notes; action plans; and any personal data contained in documents or policies you upload. This may include special-category data (such as health-related information) where you choose to include it.
  • Categories of data subjects: your staff, assessors and other authorised users, and any individuals referred to in the data you upload.

10. Annex 2 — Technical and organisational security measures

We maintain appropriate technical and organisational measures designed to protect Customer Personal Data, including:

  • encryption of data in transit (TLS) and encryption of data at rest by our hosting provider;
  • access controls and role-based permissions, so users see only the data appropriate to their role, and administrative access is restricted;
  • authentication managed by a specialist identity provider, with hashed credentials;
  • logical separation of each organisation’s data and rules that restrict access to a user’s own organisation;
  • use of reputable infrastructure providers that maintain recognised security certifications;
  • regular application of security updates and a process for responding to security issues; and
  • measures to help restore availability and access to data in a timely manner in the event of an incident.

These measures may be updated over time to reflect technical developments, provided the level of protection is not reduced.

11. Annex 3 — Approved sub-processors

Sub-processorPurposeRegion
Google Cloud / FirebaseHosting, database, authentication, file storageEuropean Economic Area
StripePayment processing and billingEU / US
AnthropicAI processing of contentUS
Google (Gemini AI)AI processing of contentUS / EEA
ResendTransactional and notification emailUS

Where a sub-processor is located outside the UK, an appropriate transfer safeguard is relied upon as described in clause 5.

12. Contact

Questions about this DPA, or requests relating to it, can be sent to chris@carewithintelligence.com. See also our Privacy Policy and Terms & Conditions.

Care With Intelligence Holdings Limited · Registered in England and Wales, company number 15513514 · Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. DPA version 1.0, effective 12 June 2026.