Legal

Data Processing Agreement

Version 1.4 · Effective date: 27 August 2026

This Data Processing Agreement ("DPA") supplements and forms part of the Terms of Service between Sandosoft Tech Limited("Processor") and your clinic ("Controller"). It governs the processing of personal data by the Processor on behalf of the Controller in connection with the SandoAssist WhatsApp booking service. By checking "I agree to the DPA" at registration, your clinic accepts this DPA electronically as of the date of registration — this constitutes execution of the agreement in the same way a signature would.

Sandosoft Tech Limitedis registered with the UK Information Commissioner's Office (ICO) as a data controller/processor under registration reference ZC225325.

1. Definitions

  • UK GDPR — the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.
  • Personal Data — any information relating to an identified or identifiable natural person, as defined in Article 4(1) UK GDPR.
  • Processing — any operation performed on Personal Data, including collection, storage, retrieval, transmission, and deletion.
  • Data Subject — a patient or other individual whose Personal Data is processed under this DPA.
  • Sub-processor — any third party engaged by the Processor to carry out processing on behalf of the Controller.
  • Security Incident — any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

2. Subject matter and duration

The Processor processes Personal Data on behalf of the Controller for the purpose of operating the SandoAssist AI-powered WhatsApp booking service, including:

  • Receiving and processing WhatsApp messages from patients;
  • Identifying appointment availability and making bookings in the Controller's practice management system;
  • Sending appointment reminders and confirmations to patients;
  • Generating booking reports for the Controller.

This DPA commences on the date the Controller registers for the service and continues until the service agreement is terminated.

3. Personal data processed

CategoryExamplesSensitivity
Contact detailsWhatsApp phone number, nameStandard
Appointment informationDate, time, service type, practitionerStandard
Health-related informationCondition or symptom described in booking messageSpecial category (Art. 9 UK GDPR)

The Controller acknowledges that patients may volunteer special-category health data in their WhatsApp messages. The Processor processes such data solely to the extent necessary to route the booking request and does not use it for any other purpose.

4. Obligations of the Processor

  • Process Personal Data only on documented instructions from the Controller, as set out in this DPA and the Terms of Service;
  • Ensure that persons authorised to process the data are bound by appropriate confidentiality obligations;
  • Implement the technical and organisational security measures described in clause 7;
  • Assist the Controller in fulfilling its obligations under UK GDPR Articles 32–36 (security, DPIAs, prior consultation);
  • At the Controller's election, delete or return all Personal Data on termination of the service, and delete existing copies unless storage is required by law;
  • Make available to the Controller information necessary to demonstrate compliance with this DPA, and permit audits as described in clause 9;
  • Notify the Controller without undue delay if an instruction is considered to infringe UK GDPR or applicable data protection law.

5. Obligations of the Controller

The Controller warrants and undertakes that:

  • It has a valid lawful basis under UK GDPR Article 6 (and Article 9 for special-category data) for processing patient data via the service;
  • It has informed patients that a WhatsApp-based AI booking assistant is used, and how their data will be processed;
  • It will keep its login credentials secure and notify the Processor immediately if it suspects unauthorised access;
  • It will not instruct the Processor to process data in a manner that violates applicable law.

6. Sub-processors

The Controller provides general written authorisation for the Processor to engage the following sub-processors:

Sub-processorCountryPurpose
Meta Platforms Inc.USAWhatsApp Business API — message routing
Anthropic PBCUSAAI language model — generates booking bot responses
Supabase Inc.United KingdomDatabase hosting — conversations, messages, clinic configuration
Railway Corp.Netherlands (EU West)Backend application hosting
Vercel Inc.United KingdomDashboard hosting and CDN
Brevo (Sendinblue SA)European Union (France)Transactional email (confirmations, reports)
StripeEU / USAPayment processing — subscription billing
SentryGermany (EU)Error monitoring

The Processor will notify the Controller of any intended changes to sub-processors by email at least 14 days in advance, giving the Controller the opportunity to object on reasonable grounds, and imposes data protection obligations on each sub-processor equivalent to those set out in this DPA.

7. Technical and organisational security measures

  • Encryption in transit using TLS 1.2 or higher for all data transfers;
  • Encryption at rest for all database storage;
  • Access controls limiting database access to authenticated application services;
  • Role-based access within the dashboard — clinic staff cannot access other clinics' data;
  • Multi-tenant data isolation — each clinic's data is scoped by clinic ID at the database query level;
  • Regular dependency updates and automated security scanning;
  • Error monitoring and alerting for system failures;
  • No hardcoded credentials in source code — all secrets held in environment variables.

8. Security incident notification

The Processor will notify the Controller of a Security Incident without undue delay and, where feasible, within 48 hours of becoming aware of it, including a description of its nature, the categories and approximate number of data subjects affected, likely consequences, and measures taken. The Controller is responsible for notifying the ICO within 72 hours of becoming aware (Article 33 UK GDPR) and, where required, informing affected data subjects.

9. Audit rights

On reasonable written request (no less than 14 days' notice), the Processor will provide information reasonably required to verify compliance with this DPA. The Controller may conduct an audit no more than once per calendar year; the Processor may charge reasonable costs for assistance beyond document provision. Any third-party auditor must be bound by an appropriate non-disclosure obligation.

10. Data subject rights

Where a data subject request is received directly by the Processor and properly relates to the Controller's processing, it will be promptly forwarded to the Controller. The Processor provides reasonable assistance with UK GDPR Articles 15–22 (access, rectification, erasure, restriction, portability, objection).

Right to erasure (Article 17): the Controller may submit a deletion request for a specific patient via the admin API. All messages and conversation records for that patient are deleted within 24 hours.

11. Data retention and deletion

  • Personal Data is retained for no longer than 12 months from the date of the last interaction with the data subject, after which it is automatically purged.
  • On termination of the service, within 30 days the Processor will provide a data export on request and permanently delete all Personal Data relating to the Controller's patients from its systems and sub-processors.
  • The Processor may retain anonymised or aggregated data that cannot reasonably be used to identify any individual.

12. International data transfers

Personal Data may be transferred to sub-processors located outside the UK/EEA (see clause 6). Any such transfer is made under one of: the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses; an adequacy decision by the UK Secretary of State; or other appropriate safeguards permitted under UK GDPR Chapter V. Message content sent to Anthropic (USA) to generate responses is covered by Anthropic's standard contractual clauses; Anthropic does not use API data to train models.

13. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.

14. Execution

This DPA is executed electronically: by checking "I agree to the Data Processing Agreement" during registration, the individual registering confirms they are authorised to bind the clinic named on the account, and the clinic thereby accepts this DPA as Data Controller. Sandosoft Tech Limited accepts this DPA as Data Processor by accepting the clinic's registration. A record of acceptance (clinic, date, and DPA version) is retained for audit purposes.

Contact

Sandosoft Tech Limited
Email: hello@sandoassist.com