Version 1.4 · Effective date: 27 August 2026
This Data Processing Agreement ("DPA") supplements and forms part of the Terms of Service between Sandosoft Tech Limited("Processor") and your clinic ("Controller"). It governs the processing of personal data by the Processor on behalf of the Controller in connection with the SandoAssist WhatsApp booking service. By checking "I agree to the DPA" at registration, your clinic accepts this DPA electronically as of the date of registration — this constitutes execution of the agreement in the same way a signature would.
Sandosoft Tech Limitedis registered with the UK Information Commissioner's Office (ICO) as a data controller/processor under registration reference ZC225325.
The Processor processes Personal Data on behalf of the Controller for the purpose of operating the SandoAssist AI-powered WhatsApp booking service, including:
This DPA commences on the date the Controller registers for the service and continues until the service agreement is terminated.
| Category | Examples | Sensitivity |
|---|---|---|
| Contact details | WhatsApp phone number, name | Standard |
| Appointment information | Date, time, service type, practitioner | Standard |
| Health-related information | Condition or symptom described in booking message | Special category (Art. 9 UK GDPR) |
The Controller acknowledges that patients may volunteer special-category health data in their WhatsApp messages. The Processor processes such data solely to the extent necessary to route the booking request and does not use it for any other purpose.
The Controller warrants and undertakes that:
The Controller provides general written authorisation for the Processor to engage the following sub-processors:
| Sub-processor | Country | Purpose |
|---|---|---|
| Meta Platforms Inc. | USA | WhatsApp Business API — message routing |
| Anthropic PBC | USA | AI language model — generates booking bot responses |
| Supabase Inc. | United Kingdom | Database hosting — conversations, messages, clinic configuration |
| Railway Corp. | Netherlands (EU West) | Backend application hosting |
| Vercel Inc. | United Kingdom | Dashboard hosting and CDN |
| Brevo (Sendinblue SA) | European Union (France) | Transactional email (confirmations, reports) |
| Stripe | EU / USA | Payment processing — subscription billing |
| Sentry | Germany (EU) | Error monitoring |
The Processor will notify the Controller of any intended changes to sub-processors by email at least 14 days in advance, giving the Controller the opportunity to object on reasonable grounds, and imposes data protection obligations on each sub-processor equivalent to those set out in this DPA.
The Processor will notify the Controller of a Security Incident without undue delay and, where feasible, within 48 hours of becoming aware of it, including a description of its nature, the categories and approximate number of data subjects affected, likely consequences, and measures taken. The Controller is responsible for notifying the ICO within 72 hours of becoming aware (Article 33 UK GDPR) and, where required, informing affected data subjects.
On reasonable written request (no less than 14 days' notice), the Processor will provide information reasonably required to verify compliance with this DPA. The Controller may conduct an audit no more than once per calendar year; the Processor may charge reasonable costs for assistance beyond document provision. Any third-party auditor must be bound by an appropriate non-disclosure obligation.
Where a data subject request is received directly by the Processor and properly relates to the Controller's processing, it will be promptly forwarded to the Controller. The Processor provides reasonable assistance with UK GDPR Articles 15–22 (access, rectification, erasure, restriction, portability, objection).
Right to erasure (Article 17): the Controller may submit a deletion request for a specific patient via the admin API. All messages and conversation records for that patient are deleted within 24 hours.
Personal Data may be transferred to sub-processors located outside the UK/EEA (see clause 6). Any such transfer is made under one of: the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses; an adequacy decision by the UK Secretary of State; or other appropriate safeguards permitted under UK GDPR Chapter V. Message content sent to Anthropic (USA) to generate responses is covered by Anthropic's standard contractual clauses; Anthropic does not use API data to train models.
This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.
This DPA is executed electronically: by checking "I agree to the Data Processing Agreement" during registration, the individual registering confirms they are authorised to bind the clinic named on the account, and the clinic thereby accepts this DPA as Data Controller. Sandosoft Tech Limited accepts this DPA as Data Processor by accepting the clinic's registration. A record of acceptance (clinic, date, and DPA version) is retained for audit purposes.
Sandosoft Tech Limited
Email: hello@sandoassist.com