This Data Processing Agreement ("DPA") forms part of the Terms of Service between North & Main Ltd ("Denbot", "Processor") and the customer ("Customer", "Controller") and applies whenever Denbot processes personal data on the Customer's behalf. It is designed to meet Article 28 of the UK GDPR.
For personal data submitted through the Customer's use of Denbot — such as patient and enquiry data — the Customer is the controller and Denbot is the processor. Denbot processes such data only on the Customer's documented instructions, including as set out in the Terms of Service and this DPA.
The subject matter is the provision of the Denbot service. Processing continues for the duration of the Customer's subscription and until data is deleted or returned in accordance with this DPA.
Denbot processes personal data to capture, store, organise, and route enquiries and leads; to power CRM, inbox, messaging, automation, and reporting features; and to provide support, in each case to deliver the service to the Customer.
The Customer must not use the service to process special category data except where it has a lawful basis and appropriate safeguards in place; any clinical/health details a patient volunteers in an enquiry are provided at the Customer's direction as controller.
Denbot maintains measures including encryption of data in transit, access controls and authentication, logical separation (tenant isolation) of each Customer's data, and monitoring. Measures are reviewed and updated as appropriate.
The Customer authorises Denbot to engage sub-processors (for example, cloud hosting, database, email/SMS/WhatsApp delivery, and payment providers) to support the service. Denbot imposes data protection obligations on sub-processors that are consistent with this DPA and remains responsible for their performance. We will provide notice of intended changes to sub-processors and give the Customer the opportunity to object on reasonable data-protection grounds.
Where personal data is transferred outside the UK, Denbot ensures an appropriate transfer mechanism is in place, such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
Denbot will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide information reasonably available to help the Customer meet its own notification obligations.
Taking into account the nature of the processing, Denbot will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a data subject contacts Denbot directly about Customer Data, we will refer them to the Customer.
On termination, the Customer may export its data for a reasonable period. After that, Denbot will delete or return the personal data, unless retention is required by law.
Denbot will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits.
This DPA is governed by the laws of England & Wales and forms part of the Terms of Service.
North & Main Ltd — privacy@denbot.co.uk