Legal & GDPR
Last updated 21 June 2026
This Data Processing Agreement (DPA) forms part of the Partner Terms of Service or other agreement between Icletns and the Business for use of the Platform.
The Business is the Controller and Icletns is the Processor for Customer Personal Data processed by Icletns on the Business's behalf.
Icletns acts as an independent controller for business account administration, authentication, subscription billing, support, security, fraud prevention, legal compliance, and its own Platform operations. Those activities are outside this DPA and are described in the Privacy Notice.
Terms such as Controller, Processor, Personal Data, Processing, Data Subject, Personal Data Breach, and Supervisory Authority have the meanings given by applicable Data Protection Law.
Data Protection Law means the UK GDPR, Data Protection Act 2018, PECR, and, where applicable to the Processing, the EU GDPR and relevant national implementing law, each as amended or replaced.
The Platform is not medical software, an electronic health-record system, or a clinical-records platform. Any future Processing of regulated health data would require a separate written addendum, documented product and security controls, and an appropriate compliance assessment before Processing begins.
Icletns will process Customer Personal Data only:
Icletns will immediately inform the Business if, in its opinion, an instruction infringes Data Protection Law. Icletns may suspend the affected Processing until the parties resolve the issue.
The Business is responsible for ensuring that its instructions, collection, use, disclosures, retention, and communications comply with Data Protection Law.
Icletns will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data-protection and security guidance.
Icletns will implement technical and organisational measures appropriate to the risks, including as applicable:
The Business is responsible for its devices, credentials, user permissions, integrations, exports, and lawful configuration of the Platform.
Icletns will notify the Business without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notice will include available information concerning:
Information may be provided in phases as it becomes available. Notification does not constitute an admission of fault.
The Business is responsible for determining whether to notify a Supervisory Authority or Data Subjects. Icletns will provide reasonable assistance, taking into account the nature of Processing and information available to it.
If Icletns receives a request relating to Customer Personal Data, it will refer the requester to the Business or forward the request where appropriate, unless prohibited by law.
Taking into account the nature of Processing, Icletns will provide reasonable technical and organisational assistance for access, rectification, erasure, restriction, portability, objection, and other applicable rights.
The Business remains responsible for verifying the requester, deciding the response, and meeting statutory deadlines.
Taking into account the nature of Processing and information available, Icletns will provide reasonable assistance with:
Additional assistance outside standard Platform functionality may be charged at reasonable rates where permitted and agreed in advance.
The Business gives Icletns general written authorisation to appoint Subprocessors needed to provide the Platform.
Subprocessor categories may include cloud hosting, database, storage, authentication, transactional communications, file delivery, support, security, and error-monitoring providers.
Current Subprocessors, their purposes, and relevant processing information are published in the Subprocessor List. Third-party payment providers used only for Icletns subscription billing are not appointed under this DPA to process or settle appointment-related transactions. If a payment provider processes Customer Personal Data on Icletns's behalf for an expressly introduced feature, it must first be added to the Subprocessor List and governed by appropriate terms.
Icletns will:
The Business may object on reasonable data-protection grounds within 30 days of notice. The parties will work in good faith on a reasonable alternative. If none is available, either party may terminate the affected service without penalty for the unused prepaid period.
Icletns will not make a restricted transfer of Customer Personal Data unless the transfer is covered by a lawful transfer mechanism. A transfer is treated as restricted only where the applicable Data Protection Law's international-transfer rules apply to the actual data flow and recipient.
Mechanisms may include:
Icletns will complete transfer risk assessments and implement supplementary measures where required. Information about applicable mechanisms will be made available to the Business on reasonable request.
The Standard Contractual Clauses, UK Addendum, or International Data Transfer Agreement apply only where required for an actual restricted transfer. The exporter, importer, applicable module, governing law, competent authority, and annex information will be determined by the parties' actual roles, locations, and data flow and documented as required. No transfer mechanism is required solely because the Business and Icletns enter into this DPA.
Icletns will make available information reasonably necessary to demonstrate compliance with this DPA.
The Business may conduct an audit no more than once in any 12-month period, unless required by a Supervisory Authority or following a material security incident. Audits must:
The Business bears its audit costs. Icletns may charge reasonable costs for disproportionate assistance.
During the Subscription, the Business may export Customer Personal Data using available Platform functionality.
After termination, Icletns will make a reasonable export available on request for at least 30 days. Icletns will then delete Customer Personal Data from active systems within 60 days after the export period ends and from backups within a further 90 days, unless:
Retained data remains protected and is not used for another purpose.
The Business warrants that:
Liability arising under this DPA is subject to the liability provisions in the Partner Terms, except to the extent Data Protection Law prohibits a limitation.
If this DPA conflicts with the Partner Terms on Processing of Customer Personal Data, this DPA prevails.
This DPA begins when Icletns first processes Customer Personal Data for the Business and continues until that Processing ends.
Icletns may suspend Processing that infringes Data Protection Law or creates a material security risk. If compliance cannot be restored within a reasonable period, either party may terminate the affected Processing.
Data-protection notices under this DPA may be sent to [email protected] and to the Business contact recorded in the Platform.