Version v1
Data Processing Agreement
This agreement is required by law. Article 28(3) of the UK GDPR requires a written contract whenever one organisation processes personal data on another's behalf. CuraFlow Care stores health and care information about identifiable people — special category data under Article 9 — so this agreement must be in place before you use the service.
Parties
- Controller: your organisation (the care provider whose account this is).
- Processor: Cura Compliance UK Limited, company no. 15946204, registered in England and Wales. Registered office: Flat 4, 10 St. Marys Road, Doncaster DN1 2NP.
You decide what care data is collected and why. We only ever act on your instructions.
1. Processing on documented instructions
We will process personal data only on your documented instructions, including on transfers outside the UK, unless we are required to do otherwise by law. If we are required by law to process in some other way, we will tell you before doing so unless the law forbids us from telling you.
Your instructions are: this agreement, the Terms of Use, and your use of the features we provide. If we think an instruction breaches data protection law, we will tell you.
2. Confidentiality
We ensure that every person authorised to process your personal data is under an appropriate duty of confidentiality, whether contractual or statutory, and that the duty survives the end of their engagement.
3. Security (Article 32)
We implement appropriate technical and organisational measures to protect personal data, taking account of the state of the art, the costs of implementation, and the risk to the people the data is about. Those measures are set out in Annex B, and include encryption in transit and at rest, role-based access control, row-level database security isolating each organisation's data, and audit logging.
4. Sub-processors
You give us general authorisation to appoint sub-processors. Our current sub-processors are listed in Annex C.
We will give you at least 30 days' notice before adding or replacing a sub-processor, so you have a genuine opportunity to object. If you reasonably object on data protection grounds, we will work with you to find a solution; if we cannot, you may terminate the affected service without penalty and receive a pro-rata refund.
We impose on every sub-processor the same data protection obligations set out in this agreement, and we remain fully liable to you for their performance.
5. Assisting with data subject rights
Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures — insofar as this is possible — in fulfilling your obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability and objection.
If a person contacts us directly about their data, we will not respond substantively. We will forward the request to you without undue delay, because you are the controller and it is your decision.
6. Assisting with security, breaches and DPIAs
We will assist you in meeting your obligations under Articles 32 to 36, taking into account the nature of processing and the information available to us. In particular:
- Personal data breaches. We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data. Our notification will describe the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures we have taken or propose to take. You remain responsible for deciding whether to notify the ICO (within 72 hours) and the people affected.
- Data protection impact assessments. We will provide the information you reasonably need to carry out a DPIA and, where required, to consult the ICO.
7. Deletion or return at the end
At your choice, we will delete or return all personal data to you at the end of the provision of services, and delete existing copies, unless UK law requires us to keep it.
In practice: your data stays available for export for 90 days after your subscription ends. After that we may delete it. Backups are purged on their normal rotation.
Please read section 5 of the Terms of Use on statutory retention. Care records must often be kept for 8 years, and children's records in some cases until the person's 75th birthday. Those obligations are yours, not ours, and you should export and archive records in your own systems.
8. Audits and demonstrating compliance
We will make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice we will respond to reasonable written questions and provide our security documentation. On-site audits may be requested once per year, on 30 days' notice, at your cost, subject to confidentiality, and arranged so as not to disrupt the service for other customers. We will co-operate promptly with any audit required by the ICO.
9. International transfers
Your care data is stored in the European Economic Area (our database is hosted in Paris, eu-west-3). Where any transfer outside the UK is necessary, we will ensure an appropriate safeguard is in place under Article 46 — normally the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — together with a transfer risk assessment.
10. Liability and precedence
This agreement forms part of, and is subject to, the Terms of Use, including its limitations of liability. Where this agreement conflicts with any other agreement between us on the subject of data protection, this agreement prevails.
Annex A — Details of the processing
Subject matter: provision of the CuraFlow Care documentation service.
Duration: for as long as your subscription is active, plus the 90-day export window described in section 7.
Nature and purpose: storing, organising, structuring, retrieving, displaying and exporting care documentation, so that your organisation can record and evidence the care it delivers.
Categories of data subject:
- People receiving care and support from your organisation ("service users"), including in some cases children and young people.
- Your staff, workers and volunteers who use the service.
- In some cases, family members, next of kin, advocates and named contacts recorded within a care plan.
Types of personal data:
- Identifiers: name, date of birth, address, contact details, internal reference numbers, NHS number where you record it.
- Special category data (Article 9): health and care needs, diagnoses, medication, mental and physical health, disability, and — where you record them — race or ethnic origin, religious or philosophical beliefs, sex life and sexual orientation.
- Risk assessments, incident records, behaviour support information and safeguarding notes.
- Staff data: name, work email, role, and the audit trail of entries each user created or amended.
Special category condition: you are responsible for identifying your lawful basis under Article 6 and your condition under Article 9 — typically Article 9(2)(h), health or social care, read with Schedule 1 Part 1 of the Data Protection Act 2018, which also requires you to have an appropriate policy document in place.
Annex B — Technical and organisational measures
- Encryption: TLS 1.2+ for all data in transit; encryption at rest for the database and all backups.
- Access control: individual named accounts, password authentication, role-based permissions. Row-level security in the database isolates each organisation's data, enforced by the database itself rather than by application code alone.
- Least privilege: our staff do not access customer care data in the ordinary course. Access for support purposes is limited to named personnel, requires a business reason, and is logged.
- Audit logging: entries record who created or amended them and when.
- Backups: encrypted managed backups on a rolling retention cycle, with restoration tested periodically.
- Segregation: production data is never copied into development or test environments.
- Resilience: managed hosting with automated failover and monitoring.
- Staff: confidentiality obligations in contracts; data protection awareness training.
- Vulnerability management: dependencies monitored and patched; security headers and a content security policy applied.
Annex C — Approved sub-processors
- Supabase — database, authentication and file storage. Processing location: EEA, Paris (eu-west-3).
- Vercel Inc. — application hosting and delivery. Processing in EEA regions; the company is US-headquartered.
- Resend — transactional email only (account and notification emails). No care records are sent to Resend. EU processing region.
We do not send care records to any artificial intelligence provider. CuraFlow Care has no AI features.
Signature
By typing your full name below you confirm that:
- you are authorised to enter into this agreement on behalf of your organisation;
- your organisation is the controller of the personal data it processes using CuraFlow Care; and
- you accept this Data Processing Agreement in full.
A copy of this agreement exactly as shown to you, together with your name, the date and your IP address, is stored as a record of signature and cannot afterwards be edited or deleted.
Customers sign this when they first use CuraFlow Care. A signed copy is available in your account. See also the Terms of Use and Privacy Notice.