Back to Home

Intellicons Technology Ltd

Data Processing Agreement

Version 1.0 · Last updated June 2026 · UK GDPR Article 28 compliant

Intellicons Technology Ltd · getclinic.io · Last updated: June 2026 · Version 1.0

1. Introduction and Parties

This Data Processing Agreement ("DPA") is entered into between:

  • Data Controller: The prescriber, clinic, or organisation ("you", "Controller") registered on the GetClinic platform, who determines the purposes and means of processing patient personal data.
  • Data Processor: Intellicons Technology Ltd (Company No: 17267394), trading as GetClinic, a company registered in England and Wales, registered address: 14/2E Docklands Business Centre, 10-16 Tiller Road, London, E14 8PX ("GetClinic", "Processor"), who processes personal data on behalf of the Controller.

This DPA forms part of, and is incorporated into, the GetClinic Terms of Service. By accepting the Terms of Service and using the GetClinic platform to process patient data, you agree to this DPA. This DPA applies to all processing of personal data (including special category health data) that GetClinic carries out on your behalf as a Data Processor.

2. Definitions

In this DPA, the following terms have the meanings set out below:

  • "UK GDPR" means the UK General Data Protection Regulation as it forms part of domestic law by virtue of the European Union (Withdrawal) Act 2018.
  • "Data Protection Act 2018" means the Data Protection Act 2018 as amended from time to time.
  • "Personal Data" has the meaning given to it under Article 4(1) UK GDPR.
  • "Special Category Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning a person's sex life or sexual orientation.
  • "Processing" has the meaning given to it under Article 4(2) UK GDPR.
  • "Sub-processor" means any third party engaged by GetClinic to process Personal Data on behalf of the Controller.

3. Subject Matter, Duration, Nature and Purpose of Processing

  • Subject matter: Patient personal data and clinical records entered into the GetClinic platform by the Controller.
  • Duration: For the duration of the Controller's subscription to GetClinic, plus any retention period required by applicable law.
  • Nature of processing: Collection, storage, retrieval, use, disclosure, and deletion of patient personal data to operate the GetClinic e-prescribing and patient management platform.
  • Purpose: To enable the Controller to manage patient records, issue electronic prescriptions, schedule appointments, facilitate pharmacy dispatch, and carry out other clinical workflow tasks via the GetClinic platform.
  • Categories of data subjects: Patients of the Controller.
  • Categories of personal data: Full name, date of birth, contact details, medical history, medication records, prescription records, allergy information, clinical notes, consultation records, laboratory results, consent records, and payment information (processed via Stripe).
  • Special category data: Health data processed under Article 9(2)(h) UK GDPR — processing necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health care, or the management of health care systems.

4. Controller's Obligations

The Controller warrants and represents that:

  • It is duly authorised to process the personal data it enters into the GetClinic platform and has a lawful basis for all such processing under UK GDPR.
  • It has obtained all necessary consents, authorisations, and/or has a lawful basis for processing special category health data under Article 9 UK GDPR.
  • It has provided patients with appropriate privacy notices explaining how their data will be processed, including that it may be processed by GetClinic as a data processor.
  • It will only instruct GetClinic to process personal data in accordance with applicable data protection law.
  • It is responsible for ensuring the accuracy and completeness of personal data entered into the platform.
  • It will respond to data subject rights requests from patients within the statutory timeframes, using data exported from the GetClinic platform as required.

5. GetClinic's Obligations as Data Processor

GetClinic, as Data Processor, shall:

  • Process personal data only on documented instructions from the Controller (including as set out in this DPA and the Terms of Service), unless required to do so by applicable UK law.
  • Ensure that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Clause 6 of this DPA.
  • Not engage any sub-processor without the Controller's prior general written authorisation (given through acceptance of this DPA) and subject to the conditions set out in Clause 7.
  • Assist the Controller, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to data subject rights requests.
  • Assist the Controller in ensuring compliance with its obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs, prior consultation).
  • At the Controller's choice, delete or return all personal data to the Controller after the end of the provision of processing services, and delete existing copies unless UK law requires storage of the data.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 UK GDPR.

6. Technical and Organisational Security Measures

GetClinic implements the following technical and organisational measures to protect personal data:

  • TLS 1.3 encryption for all data in transit between users and the platform
  • AES-256 encryption for all data at rest on AWS infrastructure (eu-west-1 / eu-west-2)
  • Role-based access controls (RBAC) ensuring each user can access only data necessary for their role
  • Bcrypt hashing for all passwords and prescriber PINs — plaintext credentials are never stored
  • Multi-factor authentication available for all accounts
  • Regular penetration testing and vulnerability assessments
  • Comprehensive audit logging of all prescription and clinical data access events, retained for a minimum of 8 years
  • Advanced Electronic Signatures (AES) for all prescriptions, creating a tamper-evident record
  • Automated session timeouts and IP-based fraud detection
  • Row-level security at the database layer to prevent cross-clinic data access
  • Data hosted exclusively in UK/EU-compliant AWS regions — patient data does not leave the UK/EEA

7. Sub-Processors

The Controller grants GetClinic general authorisation to engage sub-processors. GetClinic shall maintain a list of approved sub-processors and notify the Controller of any intended changes at least 30 days before the change takes effect, giving the Controller the opportunity to object.

Current approved sub-processors include:

  • Amazon Web Services (AWS): Cloud infrastructure hosting — EU/UK regions only (eu-west-1, eu-west-2). Transfer safeguards: UK IDTA.
  • Vercel Inc: Application hosting and content delivery. Transfer safeguards: Standard Contractual Clauses.
  • Supabase Inc: Database services (PostgreSQL). Transfer safeguards: Standard Contractual Clauses; data hosted in EU regions.
  • Stripe Inc: Payment processing. Transfer safeguards: Standard Contractual Clauses. Stripe processes payment data only; clinical patient data is not shared with Stripe.

Each sub-processor is bound by a data processing agreement that imposes data protection obligations no less protective than those in this DPA.

8. International Data Transfers

GetClinic will not transfer personal data outside the UK/EEA without ensuring adequate safeguards are in place in accordance with UK GDPR. Patient clinical data is stored exclusively in AWS UK/EU regions. Where any transfer occurs (e.g., via sub-processors), GetClinic relies on:

  • UK International Data Transfer Agreements (UK IDTA) incorporating the UK Addendum to EU Standard Contractual Clauses.
  • UK adequacy decisions where applicable.

9. Data Breach Notification

GetClinic shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's patient data. The notification will include:

  • A description of the nature of the breach including categories and approximate number of data subjects and personal data records concerned.
  • The name and contact details of the Data Protection Officer (compliance@getclinic.io).
  • A description of the likely consequences of the breach.
  • A description of the measures taken or proposed to address the breach.

The Controller is responsible for notifying affected data subjects and the ICO in accordance with Articles 33–34 UK GDPR where required.

10. Data Subject Rights Assistance

GetClinic will, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to respond to data subject rights requests (access, rectification, erasure, portability, restriction, objection). The Controller may export patient data from the platform at any time to assist with such requests. GetClinic will respond to direct data subject enquiries by directing the data subject to the Controller (their prescriber).

11. Audit Rights

GetClinic shall make available to the Controller all information necessary to demonstrate compliance with Article 28 UK GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality requirements. GetClinic may satisfy this obligation by providing up-to-date third-party audit reports, certifications, or SOC 2 reports from its sub-processors.

12. Deletion or Return of Data

Upon termination of the Controller's subscription, GetClinic will, at the Controller's request, return all personal data in a structured, commonly used, machine-readable format, or securely delete it, within 30 days of the request. GetClinic may retain personal data beyond this period only where required by applicable UK law (e.g., clinical records retention requirements under GPhC and NHS guidance — minimum 8 years).

13. Governing Law

This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA are subject to the exclusive jurisdiction of the courts of England and Wales.

14. Contact

Data Protection / DPA enquiries: compliance@getclinic.io
General support: support@getclinic.io
Company: Intellicons Technology Ltd · Company No: 17267394
Registered Address: 14/2E Docklands Business Centre, 10-16 Tiller Road, London, E14 8PX