Legal & GDPR

Data Processing Agreement

Last updated 21 June 2026

This Data Processing Agreement (DPA) forms part of the Partner Terms of Service or other agreement between Icletns and the Business for use of the Platform.

1. Parties and Roles

The Business is the Controller and Icletns is the Processor for Customer Personal Data processed by Icletns on the Business's behalf.

Icletns acts as an independent controller for business account administration, authentication, subscription billing, support, security, fraud prevention, legal compliance, and its own Platform operations. Those activities are outside this DPA and are described in the Privacy Notice.

Terms such as Controller, Processor, Personal Data, Processing, Data Subject, Personal Data Breach, and Supervisory Authority have the meanings given by applicable Data Protection Law.

2. Applicable Data Protection Law

Data Protection Law means the UK GDPR, Data Protection Act 2018, PECR, and, where applicable to the Processing, the EU GDPR and relevant national implementing law, each as amended or replaced.

3. Processing Details

  • Subject matter: provision of SaaS booking, scheduling, storage, communication, support, and security functionality.
  • Duration: the Subscription term plus the export, deletion, backup, and legally required retention periods.
  • Nature: collection, recording, organisation, storage, retrieval, transmission, display, support, deletion, and other operations required to provide the Platform.
  • Purpose: operation of the Business's booking form and administration tools according to the Business's instructions.
  • Data subjects: Customers, prospective Customers, Business staff, contractors, and authorised users.
  • Personal data: names, email addresses, telephone numbers, appointment details, selected services and staff, schedules, booking history, communications, identifiers, and relevant technical or security data.
  • Special-category health data: prohibited under the standard service. The Business must not submit medical records, clinical notes, diagnoses, treatment histories, or other special-category health data.

The Platform is not medical software, an electronic health-record system, or a clinical-records platform. Any future Processing of regulated health data would require a separate written addendum, documented product and security controls, and an appropriate compliance assessment before Processing begins.

4. Documented Instructions

Icletns will process Customer Personal Data only:

  • To provide, secure, maintain, and support the Platform.
  • As configured or submitted by the Business and its authorised users.
  • As otherwise documented in the agreement or written instructions accepted by Icletns.
  • Where required by law, after informing the Business unless law prohibits notice.

Icletns will immediately inform the Business if, in its opinion, an instruction infringes Data Protection Law. Icletns may suspend the affected Processing until the parties resolve the issue.

The Business is responsible for ensuring that its instructions, collection, use, disclosures, retention, and communications comply with Data Protection Law.

5. Confidentiality

Icletns will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data-protection and security guidance.

6. Security Measures

Icletns will implement technical and organisational measures appropriate to the risks, including as applicable:

  • Role-based access and least-privilege controls.
  • Authentication and session security.
  • Encryption in transit and provider-supported encryption at rest.
  • Logging, monitoring, vulnerability management, and incident response.
  • Data validation and protection against unauthorised access.
  • Backup, recovery, availability, and resilience controls.
  • Staff confidentiality and access-management procedures.
  • Service-provider due diligence and contractual protections.
  • Secure deletion or anonymisation processes.
  • Periodic review of security measures.

The Business is responsible for its devices, credentials, user permissions, integrations, exports, and lawful configuration of the Platform.

7. Personal Data Breaches

Icletns will notify the Business without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notice will include available information concerning:

  • The nature of the breach.
  • Affected data and Data Subjects.
  • Likely consequences.
  • Measures taken or proposed.
  • A contact point for further information.

Information may be provided in phases as it becomes available. Notification does not constitute an admission of fault.

The Business is responsible for determining whether to notify a Supervisory Authority or Data Subjects. Icletns will provide reasonable assistance, taking into account the nature of Processing and information available to it.

8. Data Subject Requests

If Icletns receives a request relating to Customer Personal Data, it will refer the requester to the Business or forward the request where appropriate, unless prohibited by law.

Taking into account the nature of Processing, Icletns will provide reasonable technical and organisational assistance for access, rectification, erasure, restriction, portability, objection, and other applicable rights.

The Business remains responsible for verifying the requester, deciding the response, and meeting statutory deadlines.

9. Compliance Assistance

Taking into account the nature of Processing and information available, Icletns will provide reasonable assistance with:

  • Security obligations.
  • Personal Data Breach assessments and notifications.
  • Data protection impact assessments.
  • Prior consultation with Supervisory Authorities.
  • Records and information reasonably needed to demonstrate compliance.

Additional assistance outside standard Platform functionality may be charged at reasonable rates where permitted and agreed in advance.

10. Subprocessors

The Business gives Icletns general written authorisation to appoint Subprocessors needed to provide the Platform.

Subprocessor categories may include cloud hosting, database, storage, authentication, transactional communications, file delivery, support, security, and error-monitoring providers.

Current Subprocessors, their purposes, and relevant processing information are published in the Subprocessor List. Third-party payment providers used only for Icletns subscription billing are not appointed under this DPA to process or settle appointment-related transactions. If a payment provider processes Customer Personal Data on Icletns's behalf for an expressly introduced feature, it must first be added to the Subprocessor List and governed by appropriate terms.

Icletns will:

  • Impose data-protection obligations materially equivalent to this DPA.
  • Remain responsible for each Subprocessor's performance of those obligations.
  • Publish or otherwise make available the current Subprocessor list.
  • Give reasonable advance notice of a new or replacement Subprocessor.

The Business may object on reasonable data-protection grounds within 30 days of notice. The parties will work in good faith on a reasonable alternative. If none is available, either party may terminate the affected service without penalty for the unused prepaid period.

11. International Transfers

Icletns will not make a restricted transfer of Customer Personal Data unless the transfer is covered by a lawful transfer mechanism. A transfer is treated as restricted only where the applicable Data Protection Law's international-transfer rules apply to the actual data flow and recipient.

Mechanisms may include:

  • UK adequacy regulations.
  • The UK International Data Transfer Agreement.
  • The UK Addendum to European Commission Standard Contractual Clauses.
  • European Commission Standard Contractual Clauses where EU GDPR applies.
  • Another legally recognised safeguard or derogation.

Icletns will complete transfer risk assessments and implement supplementary measures where required. Information about applicable mechanisms will be made available to the Business on reasonable request.

The Standard Contractual Clauses, UK Addendum, or International Data Transfer Agreement apply only where required for an actual restricted transfer. The exporter, importer, applicable module, governing law, competent authority, and annex information will be determined by the parties' actual roles, locations, and data flow and documented as required. No transfer mechanism is required solely because the Business and Icletns enter into this DPA.

12. Audits and Information

Icletns will make available information reasonably necessary to demonstrate compliance with this DPA.

The Business may conduct an audit no more than once in any 12-month period, unless required by a Supervisory Authority or following a material security incident. Audits must:

  • Give at least 30 days' notice where practicable.
  • Occur during normal business hours.
  • Avoid disruption and exposure of other customers' data.
  • Use an independent auditor bound by confidentiality.
  • Prefer current third-party reports and questionnaires where sufficient.
  • Not require access to source code, trade secrets, penetration testing, vulnerability exploitation, or information relating to other customers.

The Business bears its audit costs. Icletns may charge reasonable costs for disproportionate assistance.

13. Return, Export, and Deletion

During the Subscription, the Business may export Customer Personal Data using available Platform functionality.

After termination, Icletns will make a reasonable export available on request for at least 30 days. Icletns will then delete Customer Personal Data from active systems within 60 days after the export period ends and from backups within a further 90 days, unless:

  • Law requires retention.
  • Data is required to establish, exercise, or defend legal claims.
  • A different period is agreed in writing.

Retained data remains protected and is not used for another purpose.

14. Controller Obligations

The Business warrants that:

  • It has a lawful basis for Customer Personal Data submitted to the Platform.
  • It does not submit special-category health data under the standard service.
  • It provides required privacy and cookie information.
  • Its instructions are lawful and documented.
  • Customer Personal Data is adequate, relevant, and limited to what is necessary.
  • Retention settings and deletion instructions comply with law.
  • It has authority to disclose Customer Personal Data to Icletns.
  • It will not instruct Icletns to send unlawful marketing.
  • It is responsible for responding to regulatory enquiries relating to its role as Controller.

15. Liability and Priority

Liability arising under this DPA is subject to the liability provisions in the Partner Terms, except to the extent Data Protection Law prohibits a limitation.

If this DPA conflicts with the Partner Terms on Processing of Customer Personal Data, this DPA prevails.

16. Term and Termination

This DPA begins when Icletns first processes Customer Personal Data for the Business and continues until that Processing ends.

Icletns may suspend Processing that infringes Data Protection Law or creates a material security risk. If compliance cannot be restored within a reasonable period, either party may terminate the affected Processing.

17. Contact

Data-protection notices under this DPA may be sent to [email protected] and to the Business contact recorded in the Platform.

© 2026 IClients Limited. All rights reserved.