Draft template. Replace the bracketed placeholders in lib/company.js and have a qualified solicitor review these documents before launch. Hide this notice by setting draft: false.

Data Processing Agreement

Last updated: 26 September 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Wellspring Scheduling Ltd (“Processor”, “we”) and the practice that uses Wellspring (“Controller”, “you”). It sets out how we process personal data on your behalf under Article 28 of the UK/EU GDPR.

1. Roles

For client/patient data you enter into Wellspring, you are the controller and we are the processor. You are responsible for having a lawful basis (and, for health data, a valid Article 9 condition) and for providing privacy information to your clients. Where any of your clients are minors, you are responsible for obtaining any parental or guardian consent required in your jurisdiction; our “signing on behalf of someone else” tick-box on consent forms is a tool to help you record that, not a substitute for you managing it correctly.

2. Scope of processing

  • Subject matter: providing the Wellspring service.
  • Duration: for the term of your subscription and any wind-down period.
  • Nature & purpose: hosting, storing and processing data so you can run your practice.
  • Data subjects: your clients/patients (including minors, where you treat them), contacts and staff.
  • Categories of data: contact details, appointments, invoices/payments, communications, and — where you choose to record it — health information (special category data).

3. Our obligations

  • Instructions: we process personal data only on your documented instructions (including via the app) and as needed to provide the service, unless required by law.
  • Confidentiality: personnel authorised to process data are bound by confidentiality. Where our platform staff access your account for support purposes (including “log in as” access to your admin view), that access is restricted to staff who need it and every instance is recorded in an audit log.
  • Security: we implement appropriate technical and organisational measures under Article 32 — encryption in transit, access controls, per-practice data isolation, secure authentication and audit logging.
  • Assistance: taking into account the nature of processing, we assist you in responding to data-subject requests and with your obligations under Articles 32–36 (security, breach, DPIAs).
  • Breach notification: we notify you without undue delay after becoming aware of a personal-data breach affecting your data, consistent with the timelines in section 6 for your region (e.g. supporting your 72-hour UK/EU reporting window, or Australia’s Notifiable Data Breaches scheme).
  • Deletion/return: on termination we delete or return your personal data (your choice, where feasible), except where retention is required by law. You can also export your data from the app. Deletion of the live data and of any exports we hold takes place within 30 days of termination. Backup copies are not deleted individually; they expire on the ordinary cycle described below, and all copies containing your data are gone no later than 90 days after termination. We will confirm deletion in writing on request at that point.
  • Backups: we take encrypted backups of the production database so that we can recover the service from failure, corruption or attack. Backups exist for disaster recovery only. They are not an archive, and you should not rely on them to meet your own clinical, professional or statutory record-retention obligations — you can export your data from the app at any time. We take a backup every hour, a separate daily backup at 02:00, a monthly backup on the first of each month, and a further backup immediately before we deploy any change to the service. Every backup is encrypted on our server before it leaves it. Encrypted copies are held in two places:
    • On our hosting provider’s server in Manchester, United Kingdom — the most recent 48 hourly copies (about two days), 14 daily copies, 10 pre-deployment copies and 3 monthly copies. The oldest copy held here is therefore around three months old.
    • Off-site with Backblaze, in a storage bucket in their EU Central region (section 4). Off-site copies are written to immutable storage (“Object Lock”, compliance mode) with a 30-day minimum retention which by design cannot be shortened, cancelled or overridden by anyone, including Backblaze and including us. Automatic deletion rules then remove each copy: hourly, interim and daily copies at 30 days; pre-deployment and monthly copies at 90 days.
    The practical effect is that no off-site copy exists for fewer than 30 days or more than 90 days, and no backup copy of any kind, in either location, is kept for more than approximately three months. We use immutable storage deliberately, as protection against ransomware and against an attacker who gains access to our systems attempting to destroy our backups along with the live data. The trade-off is that for the first 30 days of its life an off-site backup cannot be deleted early by anyone, including us, and including in response to an instruction from you.
  • Deleted records and backups: when you delete a record, or instruct us to delete data on your behalf, we remove it from the live service immediately; from that point it is no longer visible or accessible within Wellspring. A copy will however remain inside backups taken before the deletion until those backups expire, so a deleted record can persist in backup storage for up to approximately three months after deletion, and we are not able to remove it sooner — not because we are unwilling, but because our backup storage is deliberately built so that no one, ourselves included, can delete a copy within its retention period. While a record remains in a backup in this way we treat it as beyond use: backups are held solely for disaster recovery, they are encrypted, they are not searched or opened in the ordinary course, they are never used to restore or re-create individual records, and they are not processed for any other purpose. If we ever restore the database from a backup we will re-apply any deletions made since that backup was taken as soon as reasonably practicable, and we will tell you if your data was affected.
  • Audits: we make available information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality and notice.

4. Sub-processors

You authorise us to engage the sub-processors below to process data on your behalf. We remain responsible for their performance, and we will give reasonable notice of changes so you can object.

  • Hostinger — Application & database hosting (production) — data held in the United Kingdom (Manchester data centre, confirmed 8 Sep 2026); Hostinger International Ltd is a Lithuanian (EEA) company (Serving the app and storing data).
  • Backblaze — Encrypted off-site database backups — data held in the EU Central region (eu-central-003, EEA); Backblaze Inc. is a United States company (Disaster recovery).
  • Airtable — Internal triage board for support tickets raised by clinic staff — Airtable Inc. is a United States company and the data is processed in the United States (Handling your support requests).
  • Anthropic — AI-assisted drafting of replies to support tickets raised by clinic staff — Anthropic PBC is a United States company and the data is processed in the United States. NOT CURRENTLY ENABLED; we will give 30 days' notice before it is, and you may object (Handling your support requests).
  • Stripe — Payments & subscriptions (Card payments).
  • PayPal / Square — Payment processing (if enabled) (Card payments).
  • Meta Platforms — Advertising pixel (only with cookie consent) (Conversion tracking).
  • Resend (AWS, EU region) — Email delivery — confirmations, reminders, campaigns (Notifications).
  • Twilio — Text-message delivery — only if you connect your own Twilio account. You open the account with Twilio and pay Twilio directly; Wellspring sends your messages through it on your instruction and is not a party to your agreement with Twilio (Notifications).
  • Xero — Accounting sync (if you connect your own Xero account) (Invoices & payments).
  • Google Ireland Ltd / Microsoft Ireland Operations Ltd — Two-way calendar sync — per practitioner, only if they connect their own Google or Outlook account (Appointment sync).
  • Backblaze B2 — off-site encrypted backup storage; holds the disaster-recovery copy of the database backup described in section 3. Backblaze Inc. is incorporated in the United States and is the entity we contract with. The storage bucket we use is located in Backblaze’sEU Central region (eu-central-003), so the backup files themselves are physically held in the European Economic Area and are not stored in the United States. Section 5 explains how we treat the resulting transfer.

Support tickets. When you raise a support request with us, the ticket reference, type, status and your practice name are copied to our internal triage board (Airtable) so we can track it. The words you type — the title and the body — are not sent there; the board holds a link and we read the ticket inside Wellspring. Please still avoid putting client names or personal details into a support request: anything you type is stored in Wellspring and read by our staff.

AI-assisted support replies (not currently enabled). We have built, but have not switched on, a feature that would send the text of a support ticket to Anthropic to draft a reply. It is off for every practice. Before we enable it we will give you at least 30 days’ written notice, it will beoff by default and controlled by you in your own settings, and you may object — and if we cannot resolve your objection you may stop using the affected part of the service without penalty. We will not enable it until we have a data processing agreement and a transfer mechanism in place with Anthropic and have completed a data protection impact assessment.

Xero and Google/Microsoft calendar sync are integrations you actively choose to connect to your own account with that provider, rather than infrastructure engaged under our instructions in the ordinary sense — we list them for transparency and will confirm the correct characterisation (and any additional wording needed) with our solicitor. Any further optional integration we add in future (e.g. further accounting, calendar or marketing tools) will be added to this list, with notice, before it can be enabled on your account.

5. International transfers

The Wellspring service and its database run on a virtual private server provided by Hostinger, located in Hostinger’s Manchester, United Kingdom data centre. All live processing of your data takes place there. We will notify you before we move the hosting of the service to another country.

Our off-site database backup (section 3) is held in a Backblaze storage bucket in the European Economic Area (section 4). Because our supplier is a United States company whose personnel may be able to access the service from the United States, we treat this arrangement as an international transfer of personal data and rely on [TRANSFER MECHANISM — TO BE SETTLED WITH BACKBLAZE BEFORE SIGNATURE, see note below], supported by a documented transfer risk assessment. In addition, every file we send to Backblaze is encrypted on our server in the United Kingdom before it is transmitted. The decryption keys are held only by us, in the United Kingdom, and are never provided to Backblaze. Backblaze holds only encrypted data that it is not able to read. This corresponds to the use case the European Data Protection Board identifies as an effective supplementary measure for storage that does not require access to data in the clear.

Where a sub-processor is outside the UK/EEA, or your practice itself is based outside the UK/EEA, we ensure an appropriate transfer mechanism is in place (such as an adequacy decision or Standard Contractual Clauses).

6. Regional addenda

Where your practice is based outside the UK/EU, the following additional terms apply to our processing under this DPA:

Australia

We handle personal information in line with the Australian Privacy Principles (APPs) and will notify you of an eligible data breach in line with the Notifiable Data Breaches (NDB) scheme, in addition to our obligations under section 3.

Canada

We handle personal information in line with PIPEDA. Where your practice is subject to provincial health-privacy legislation (for example Ontario’s PHIPA), you remain responsible as controller for compliance with that legislation; we will provide reasonable assistance on request.

United States

We do not currently process data as a HIPAA business associate — see section 5 of the Terms of Service, which restricts US practices to non-insurance billing for this reason. If we later sign a Business Associate Agreement (BAA) with you, that BAA supplements this DPA and prevails over it on HIPAA-specific matters.

7. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

8. General

If there is a conflict between this DPA and the Terms on data-protection matters, this DPA prevails. This DPA is governed by the laws of England & Wales. For data-protection queries, contact help@wellspringscheduling.com.

Questions about this page? Contact us at help@wellspringscheduling.com.