Data Processing Agreement
The agreement under which we process personal data on your behalf, as required by Article 28 of the UK GDPR. It forms part of our Terms of Service.
Version 2026-07-22 · Last updated: 22 July 2026
- How this fits together
- Parties and roles
- Subject matter, duration and purpose
- Categories of data subject
- Types of personal data
- Your instructions and responsibilities
- Confidentiality and personnel
- Security measures
- Sub-processors
- Return and deletion
- Assisting you
- Personal data breaches
- Audits
- International transfers
- Liability and precedence
- Annex 1 — Details of processing
- Annex 2 — Sub-processors
- Annex 3 — Security measures
1. How this fits together
- Our Privacy Policy covers what we do as controller — website visitors, enquiries and billing contacts.
- This agreement covers what we do as processor — everything your staff enter about the people you support and about your staff.
This DPA is incorporated into our Terms of Service by reference. You accept it when you subscribe, by confirming that you have read the Terms, Privacy Policy and this agreement. We record the version, the date and time, the IP address and the email address of the person who accepted, so that both of us can evidence the agreement later.
2. Parties and roles
- Processor: SmartCareApps Ltd, company no. 17256668, 124 City Road, London EC1V 2NX.
- Controller: the care provider subscribing to the service ("you").
You determine the purposes and means of processing the personal data you enter. We process it only to provide the service, on your documented instructions.
3. Subject matter, duration, nature and purpose
- Subject matter: provision of the Smart Care Apps compliance platform.
- Duration: the term of your subscription, plus the retention and deletion timetable in section 10.
- Nature and purpose: hosting, storing, organising, displaying, exporting and deleting the records you create, so you can meet your care-compliance and CQC obligations.
4. Categories of data subject
Service users (the people you support), their next of kin and key contacts, your staff, and — where you record them — third parties named in an incident or complaint.
5. Types of personal data
Set out in full at Annex 1. It includes special-category data (health and care information), and may include criminal-offence context in safeguarding records.
6. Your instructions and responsibilities
- We process only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we tell you first, unless the law forbids it.
- You confirm you have a lawful basis (Article 6) and an Article 9 condition for the special-category data you enter, and that you have given the required privacy information to your service users and staff.
- Location processing. Where you switch on geo-tagged clock-in, you are instructing us to process your staff's location at the moment they clock in and out. You are responsible for informing your staff and holding the lawful basis and balancing test for it before enabling it.
- Free text and messaging. You are responsible for what your staff type. Records should go in the appropriate log — safeguarding, complaints — rather than in messages.
7. Confidentiality and personnel
Everyone we authorise to process your data is bound by a written confidentiality undertaking, is trained appropriately, and gets access only where needed. Support access to your account is read-only and recorded in an audit log.
8. Security measures (Article 32)
Set out at Annex 3, describing measures actually implemented — not aspirations.
9. Sub-processors
- You give general authorisation for the sub-processors listed at Annex 2.
- We will give you 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds.
- If we cannot resolve your objection, you may terminate without penalty and receive a pro-rata refund of any period paid for and not used.
- Each sub-processor is bound by terms no less protective than this agreement.
10. Return and deletion — what actually happens
This mirrors how the software actually behaves, so the contract and the product agree:
- Cancellation — your account becomes read-only for 30 days, during which an administrator can export everything: a ZIP of CSV and JSON files plus all your uploaded documents and photos.
- Closure — sign-in is disabled. Data is retained but not accessible.
- Deletion — 90 days after closure, your records and uploaded files are permanently deleted. Only a minimal tombstone remains (your organisation name and the lifecycle log), as evidence that the deletion happened.
- Backups — deletion cannot reach a backup that was already taken, so your data remains in our encrypted off-site backups until those expire. Backups are kept 60 days and then deleted automatically.
11. Assisting you
- Data subject rights. Self-serve export covers access and portability; correction and deletion are available to your administrators in the product. We will assist with anything you cannot do yourself.
- Requests made directly to us. We will not respond on your behalf. We will refer the person to you and tell you promptly, so that you can answer as the controller.
- DPIAs and prior consultation. We will give you the information you reasonably need, including our own risk assessment and Annex 3.
12. Personal data breaches
We will notify you without undue delay and in any event within 48 hours of becoming aware of a breach affecting your data, with the nature of the breach, the likely consequences, and the measures taken.
You are responsible for notifying the ICO within 72 hours where required, and affected individuals where required.
13. Audits
We will make available the information needed to demonstrate compliance with Article 28. You may audit us once in any 12-month period, on 30 days' written notice, at your own cost — and more often if a regulator requires it, or following a personal data breach affecting your data. Where our existing documentation answers your questions, providing it satisfies this clause.
14. International transfers
Our aim is UK and EU hosting and storage. The current position is set out at Annex 2:
- IONOS (hosting), Microsoft 365 (email) and postcodes.io are UK.
- Backblaze B2 (backups) is in the EU (Amsterdam). The UK recognises the EEA as adequate, so no additional transfer safeguard is required.
- Stripe (payments) is the only sub-processor transferring outside the UK and EEA, and relies on its published Data Processing Agreement incorporating the Standard Contractual Clauses and the UK Addendum.
15. Liability and precedence
Our total liability arising under or in connection with this agreement is limited to the total fees paid by you in the 12 months immediately preceding the event giving rise to the claim.
Nothing in this agreement limits liability that cannot be limited by law — including death or personal injury caused by negligence, and fraud or fraudulent misrepresentation.
This limit governs the relationship between you and us. It does not affect any right a data subject may have to claim directly against either of us under Article 82.
Where this agreement and the Terms of Service conflict on a data protection matter, this agreement prevails.
Annex 1 — Details of processing
| App | Personal data |
|---|---|
| Safeguarding Log | Service-user name, dates, abuse type, free-text detail, alleged perpetrator, MASH/CQC reporting, outcomes, comments, uploaded documents and photos. Special category. |
| Compliments, Concerns & Complaints | Names, complaint detail, status, notes, uploaded documents and photos. Possibly special category. |
| Action Tracker | Staff names as owners; free-text actions that may name individuals. |
| Audits & Checks | Staff who assign and complete; answers; uploaded evidence files. |
| Rota | Staff names, roles, contracted hours, availability, pay rates; service-user name, date of birth, address, postcode, phone, next-of-kin contact, access notes, support ratios and hours; shift allocations. |
| Rota — geo-tagged clock-in (optional, off by default) | A single staff location fix, its accuracy, the distance in metres and a verified/unverified flag, captured only at the moment of clocking in and out. No continuous or background tracking, and no movement history. |
| Messaging | Announcement text; who acknowledged and when; direct message content, sender, recipient, timestamps. |
| Accounts & audit log | Names, emails, job titles, hashed passwords, MFA secrets, roles, IP addresses and actions in the audit trail. |
Frequency: continuous for the term. Retention: per section 10.
Annex 2 — Sub-processors
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| IONOS | Server hosting — application, database and uploaded files | UK | UK hosting; data processing agreement in place |
| Backblaze B2 | Encrypted off-site backups | EU (Amsterdam) | UK adequacy for the EEA. Data is encrypted with AES-256 before it leaves our server, so the provider holds no key and cannot read it |
| Stripe | Subscription payments and card handling | US / global | Stripe's published DPA incorporating the SCCs and the UK Addendum |
| Microsoft 365 | Business email | UK | Microsoft's Data Protection Addendum |
| SMTP2GO | Transactional email — invites, resets, notices | EU | UK adequacy for the EEA; data processing agreement in place |
| postcodes.io | UK postcode to coordinates, for geo-tagged clock-in | UK | Only a postcode is sent, with no name or reference to any individual. We do not consider this to be personal data, and list it for transparency |
This list is complete as at 22 July 2026.
Annex 3 — Technical and organisational measures
- In transit: TLS throughout; a strict Content-Security-Policy; CSRF protection on every write.
- At rest: passwords hashed with bcrypt; off-site backups encrypted with AES-256 before upload, taken twice daily and proven restorable by a documented restore drill.
- Access control: role-based (admin, senior, staff), per-app assignment, and tenant isolation — every record is scoped to your organisation. Support impersonation is read-only and audit-logged.
- Authentication: multi-factor authentication is mandatory to set up — every user enrols at first sign-in — and may subsequently be switched off by that individual user. There is currently no organisation-level setting preventing a user from switching it off. Sign-in is rate-limited, and there is no user-enumeration on login or password reset.
- Auditability: an append-only activity log of significant actions, visible to your administrators.
- Data-subject tooling: self-serve export of everything (CSV, JSON and uploaded files), and the erasure lifecycle at section 10.
- Location data minimisation: captured only at clock in and out, minimum stored, no movement trail. A missing or unusable location never blocks a clock-in or clock-out; it is recorded as unverified and flagged for the manager.
- No third-party requests: the application loads nothing from third parties — even fonts are served from our own servers — so using the service does not disclose your staff's IP addresses to anyone else.
- Breach response: a documented procedure with a named lead and deputy, and the 48-hour notification commitment at section 12.