Data Processing Agreement
Last updated 2026-09-23 · Version 2026-09-23
This Data Processing Agreement ("DPA") forms part of the ChatRx Terms of Service between you, the clinic ("Controller"), and YL Digital Ltd ("Processor"). It meets the requirements of Article 28 of the UK GDPR.
1. Subject matter and duration
The Processor processes personal data only to provide the ChatRx Service to the Controller, for as long as the Terms are in force plus the return and deletion period in clause 11.
2. Nature and purpose
- Operating website chat and WhatsApp conversations with the Controller's patients and enquirers.
- Generating assistant replies.
- Sharing booking links.
- Alerting the Controller's team to clinical questions and booking requests.
- Recording opt-outs.
- Providing analytics to the Controller.
3. Types of personal data
- Name, mobile number, the messages exchanged, the page and service the chat started from, and the consent and opt-out records.
- Technical data (session identifiers, timestamps, IP address for rate-limiting and security).
- Any information patients choose to type, which may include health data (special category data under Article 9).
4. Data subjects
Patients, prospective patients and website visitors of the Controller.
5. Controller's instructions
- The Processor will process personal data only on the Controller's documented instructions: the Terms, this DPA, and the Controller's settings in the Service.
- This includes transfers set out in clause 8, unless UK law requires otherwise; in that case the Processor will tell the Controller first unless the law forbids it.
- The Processor will tell the Controller if it believes an instruction breaks data protection law.
6. Controller's obligations
- The Controller is responsible for having a lawful basis (and an Article 9 condition for health data) for the processing.
- It must give patients a transparent privacy notice that mentions the use of ChatRx and WhatsApp.
- It must obtain valid consent for WhatsApp messaging and marketing.
7. Confidentiality and security
- The Processor ensures that anyone authorised to process the data is bound by confidentiality.
- It maintains appropriate technical and organisational measures (Article 32), including: encryption in transit (TLS) and at rest; role-based access controls, with row-level security separating each clinic's data; least-privilege staff access; logging of automated agent actions; rate limiting on public endpoints; and regular review of these measures.
8. Sub-processors
- General authorisation. The Controller gives general authorisation for the Processor to use the sub-processors listed below.
- Changes. The Processor will give at least 14 days' notice by email of any new or replacement sub-processor. The Controller may object on reasonable data protection grounds; if the parties can't resolve the objection, the Controller may terminate the Service.
- Sub-processor terms. The Processor puts terms in place with each sub-processor that offer at least the same protection as this DPA, and remains liable for their performance.
- International transfers. Where a sub-processor transfers data outside the UK, the transfer relies on UK adequacy regulations or the UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses.
Current sub-processors:
- Supabase Inc: database hosting and authentication
- Cloudflare Inc: application hosting and delivery
- Lovable Labs Incorporated: application platform and AI gateway
- Google LLC: AI model used to draft assistant replies (via the AI gateway)
- Twilio Inc: WhatsApp messaging
- Meta Platforms (WhatsApp): message delivery
- Green API: internal WhatsApp alerts to the Controller's team
- Resend Inc: transactional email
9. Data subject rights
Taking into account the nature of the processing, the Processor will help the Controller respond to requests from data subjects (access, rectification, erasure, restriction, portability, objection). It will pass on any request it receives directly without responding to it itself, unless authorised.
10. Personal data breaches
The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data. It will provide the information the Controller reasonably needs to meet its own obligations, including notification to the ICO within 72 hours where required.
11. Return and deletion
When the Service ends, the Processor will make the Controller's conversation data available for export for 30 days on request. It will then delete it within a further 60 days, unless UK law requires it to be kept. Backups are overwritten in the normal backup cycle.
12. Assistance and audits
- The Processor will reasonably assist the Controller with data protection impact assessments and prior consultation with the ICO.
- It will make available the information needed to show compliance with this DPA.
- It will allow audits, at the Controller's cost, on at least 30 days' notice, no more than once a year (unless a breach has occurred). Audits must be conducted during business hours and subject to confidentiality.
13. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where the law does not allow this.
14. Precedence
If this DPA conflicts with the Terms on data protection matters, this DPA prevails.