Seventy3 OS — Data Processing Agreement
Between Seventy3 Group Ltd (Processor) and the Customer (Controller) Effective date: 13 July 2026 · Version 1.0
This Data Processing Agreement ("DPA") forms part of the customer's agreement to use the Seventy3 OS platform and governs the processing of personal data by Seventy3 Group Ltd on the customer's behalf under UK GDPR and the Data Protection Act 2018.
1. Background
(A) The Controller has entered into an agreement with the Processor under which the Processor provides the Seventy3 OS platform (the "Services"). (B) In providing the Services, the Processor processes personal data on behalf of the Controller. (C) This DPA sets out the terms on which the Processor will process personal data and the parties' obligations under UK GDPR and the Data Protection Act 2018.
2. Definitions
Capitalised terms not defined here have the meanings given in the Terms of Service. In addition:
- "Customer Personal Data" means the personal data described in Annex 1 that is processed by the Processor on behalf of the Controller under the Services Agreement.
- "Data Protection Laws" means UK GDPR, the Data Protection Act 2018, and any other applicable laws relating to the processing of personal data, in each case as amended or replaced from time to time.
- "Personal Data Breach" has the meaning given in Article 4(12) UK GDPR.
- "Services Agreement" means the Terms of Service (and any associated Order Form) between the parties.
- "Sub-processor" means any third party engaged by the Processor to process Customer Personal Data on behalf of the Controller.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022 (or its successor as in force from time to time).
- "UK IDTA" means the International Data Transfer Agreement issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (or its successor as in force from time to time).
3. Roles and scope
3.1 Roles. The Controller is the data controller and the Processor is the data processor in respect of the Customer Personal Data, for the purposes of UK GDPR Article 28.
3.2 Scope. This DPA applies to all processing of Customer Personal Data by the Processor under the Services Agreement and overrides any inconsistent terms in the Services Agreement in respect of such processing.
3.3 Subject matter and details. The subject matter, duration, nature and purpose of the processing, and the categories of data subjects and personal data, are set out in Annex 1.
4. Processor obligations
4.1 Documented instructions. The Processor will process Customer Personal Data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do so by applicable law (in which case the Processor will inform the Controller of that requirement before processing, unless the law prohibits such notice on important grounds of public interest). The Controller's documented instructions are: (a) the Services Agreement; (b) this DPA; (c) the use of the Services in their standard configuration; and (d) any further documented instructions issued by the Controller in writing (which may be by email).
4.2 Lawfulness of instructions. The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes Data Protection Laws. The Processor is not obliged to monitor the Controller's compliance with Data Protection Laws.
4.3 Confidentiality. The Processor will ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and have received appropriate data protection training.
4.4 Security. The Processor will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR. The current measures are described in Annex 2 and may be updated from time to time, provided the level of protection is not materially decreased.
4.5 Cooperation with Controller. Taking into account the nature of the processing and the information available to it, the Processor will assist the Controller in fulfilling the Controller's obligations under Articles 32 to 36 UK GDPR (security, breach notification, DPIAs, prior consultation), through appropriate technical and organisational measures.
4.6 Data subject requests. If the Processor receives a request from a data subject relating to Customer Personal Data, it will, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to respond to the request. The Processor will not respond to the data subject directly except on the documented instructions of the Controller or as required by law.
5. Sub-processors
5.1 General authorisation. The Controller authorises the Processor to engage Sub-processors to process Customer Personal Data, subject to the conditions in this clause 5. The current Sub-processors are listed in Annex 3.
5.2 Notice of changes. The Processor will give the Controller at least 30 days' prior written notice (which may be by email or in-Platform notification) of any intended addition or replacement of a Sub-processor, including the identity and processing function of the new Sub-processor.
5.3 Right to object. The Controller may object in writing to a proposed new Sub-processor within 30 days of notice, on reasonable data protection grounds. If the parties cannot resolve the objection within 30 days of receipt, the Controller may terminate the Services Agreement on written notice; in such case, the Processor will refund any pre-paid Subscription Fees relating to periods after termination.
5.4 Sub-processor obligations. The Processor will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA. The Processor remains liable to the Controller for any acts or omissions of its Sub-processors that cause the Processor to breach this DPA.
6. International transfers
6.1 Transfers. The Processor may transfer Customer Personal Data outside the United Kingdom only where one of the following applies:
- the destination country is the subject of UK adequacy regulations;
- the parties have entered into the UK IDTA, the EU Standard Contractual Clauses with the UK Addendum, or another lawful transfer mechanism;
- an exception in Article 49 UK GDPR applies.
6.2 Sub-processors outside the UK. Where a Sub-processor is located outside the UK, the Processor will ensure an appropriate transfer mechanism is in place between the Processor and the Sub-processor, and (where required) flow down protections to the Controller.
6.3 Standard Contractual Clauses. To the extent that the Processor transfers Customer Personal Data from the Controller to a country outside the UK that does not benefit from adequacy, the parties agree that the EU Standard Contractual Clauses (Module 2: Controller to Processor) and the UK Addendum are incorporated into this DPA by reference and are deemed signed by the parties as of the Effective Date, with the parties' details, transfer description, technical and organisational measures, and Sub-processor details taken from Annexes 1, 2, and 3 of this DPA. To the extent the Controller is itself a processor for a third-party controller (e.g., where the clinic acts on behalf of an NHS body), Module 3 (Processor to Processor) applies instead.
7. Personal Data Breach
7.1 Notification. The Processor will notify the Controller of any Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it.
7.2 Information. The notification will, to the extent reasonably available at the time, include:
- a description of the nature of the Personal Data Breach;
- the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address the Personal Data Breach and to mitigate its possible adverse effects;
- the name and contact details of the Processor's contact point for further information.
Where it is not possible to provide the information at the same time, it may be provided in phases without further undue delay.
7.3 Cooperation. The Processor will cooperate with the Controller and provide reasonable assistance in connection with the Controller's notifications to the Information Commissioner and to affected data subjects (where required), and in the Controller's investigation, mitigation, and remediation.
7.4 No admission. The Processor's notification of a Personal Data Breach is not an admission of fault or liability.
8. Audits
8.1 Records and information. The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Article 28 UK GDPR.
8.2 Audit by certification or report. The Controller's audit rights under Article 28(3)(h) UK GDPR are satisfied (in the first instance) by the Processor making available, on reasonable written request and no more than once per year, the most recent of: (a) any third-party security audit reports or certifications held by the Processor (e.g., SOC 2, ISO 27001), and (b) the Processor's written responses to a reasonable security questionnaire.
8.3 On-site audit. Where (a) is not available or does not, in the Controller's reasonable opinion, demonstrate the Processor's compliance with this DPA, the Controller may, at its expense and on no less than 30 days' written notice, conduct an audit of the Processor's compliance with this DPA, subject to:
- the audit being conducted by the Controller or by a qualified independent third-party auditor (other than a competitor of the Processor) bound by confidentiality;
- the audit being limited in scope to compliance with this DPA and conducted in a manner that does not unreasonably interfere with the Processor's operations;
- the audit taking place during normal business hours and at a mutually agreed date;
- the audit not occurring more than once per year, save (i) where required by a regulator or (ii) following a Personal Data Breach;
- the parties treating the results of the audit as confidential.
9. Return and deletion
9.1 During the term. During the term of the Services Agreement, the Controller may export Customer Personal Data via the Platform's standard export functions.
9.2 On termination. On termination or expiry of the Services Agreement:
- for a period of 60 days, the Processor will continue to make Customer Personal Data available for export by the Controller;
- after that period, the Processor will delete Customer Personal Data from production systems within 30 days and from routine backups within the standard backup rotation cycle of 90 days;
- the Processor will, on the Controller's written request, certify in writing that deletion has been completed.
9.3 Retained data. Notwithstanding clause 9.2, the Processor may retain Customer Personal Data to the extent required by law or in the form of properly anonymised aggregate data containing no personal data. Any retained personal data remains subject to this DPA.
10. Liability
Each party's liability under this DPA is subject to the liability provisions in the Services Agreement (including the data protection liability cap in clause 14.4 of the Terms of Service). Nothing in this clause limits liability that cannot be limited under English law (including under Article 82 UK GDPR for a data subject's claim).
11. Term, termination, and order of precedence
This DPA commences on the Effective Date and continues until the Services Agreement terminates or expires. Provisions that by their nature should survive (including return/deletion, audits, breach notification cooperation, confidentiality, and liability) survive termination.
In the event of conflict between this DPA, the Services Agreement, and any incorporated Standard Contractual Clauses (in respect of restricted transfers), the order of precedence is: (1) the Standard Contractual Clauses (in respect of the matters they cover), (2) this DPA, (3) the Services Agreement.
12. Governing law and jurisdiction
This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales, save that this clause does not affect the rights of data subjects under Article 79 UK GDPR or the jurisdiction provisions of any incorporated Standard Contractual Clauses.
Annex 1 — Subject matter and details of processing
Subject matter. Provision of the Seventy3 OS platform to the Controller in accordance with the Services Agreement.
Duration. For the term of the Services Agreement, plus the export and deletion periods set out in clause 9.
Nature and purpose. Processing of personal data to enable the Controller to operate its therapy / performance clinic, including: (a) appointment booking and management; (b) inbound communication handling (voice and SMS); (c) email and SMS automation; (d) AI-assisted clinical documentation, transcription, and summarisation; (e) exercise plan creation and delivery; (f) payment processing; (g) clinic dashboard, analytics, and reporting; and (h) related platform functions.
Categories of data subjects.
- Patients of the Controller (end-clients).
- Authorised Users of the Controller (therapists, receptionists, clinic staff).
- Other individuals whose data the Controller chooses to enter into the Platform.
Categories of personal data.
- Identity and contact data: name, email, phone, address, date of birth.
- Appointment and booking data.
- Communications data: voice call transcripts, SMS message content, email content.
- Clinical data: treatment notes, symptom descriptions, exercise prescriptions, treatment history.
- Payment data: transaction records (card numbers handled by Stripe and not stored by the Processor).
- Authorised User account data: name, email, role, access logs.
Special category data. Yes — health data within the meaning of Article 9(1) UK GDPR, including symptom descriptions captured in inbound calls or SMS messages, clinical notes, treatment history, and exercise prescriptions. The Controller is responsible for establishing the lawful basis under Article 9(2) for processing such data (typically Article 9(2)(h) for the provision of health care).
Frequency of processing. Continuous, for the duration of the Services Agreement.
Recipients. The Processor and the Sub-processors listed in Annex 3.
Retention. As set out in clause 9 (Return and deletion). The Controller is responsible for determining and instructing any longer or shorter retention required by its professional or regulatory obligations.
Data exporter (Controller)
- Name: [CUSTOMER LEGAL NAME]
- Address: [CUSTOMER REGISTERED ADDRESS]
- Contact: [CUSTOMER PRIVACY CONTACT NAME AND EMAIL]
- Activities relevant to the transfer: Operation of a therapy / performance clinic in the United Kingdom.
- Role: Controller (or, where the customer itself is a processor for a third-party controller, sub-processor in respect of the further transfer to the Processor).
Data importer (Processor)
- Name: Seventy3 Group Ltd
- Company number: 16392260
- Address: Suite 21, Call House, Enfield Street, Leeds, England, LS7 1RF
- Contact: Hamayoon Kasser, hamayoon@seventy3.co
- Activities relevant to the transfer: Provision of the Seventy3 OS clinic operating system platform.
- Role: Processor
Annex 2 — Technical and organisational measures
The Processor maintains the following technical and organisational measures, in accordance with Article 32 UK GDPR. These may be updated from time to time, provided the level of protection is not materially decreased.
1. Access control
- Role-based access control with the principle of least privilege.
- Multi-factor authentication required for all administrative and engineering access.
- Unique user IDs; no shared credentials.
- Prompt revocation of access on personnel changes.
2. Encryption
- Personal data in transit protected by TLS 1.2 or higher.
- Personal data at rest protected by AES-256 encryption (or equivalent industry standard).
- Encryption keys managed and rotated in accordance with industry practice.
3. Network security
- Firewall and network segmentation.
- Hosting infrastructure (Vercel, Supabase) provides DDoS protection and intrusion detection.
- Regular dependency monitoring and patching.
4. Logging and monitoring
- Audit logging of administrative access and changes to security-sensitive configuration.
- Authentication and access events logged and monitored for anomalies.
- Logs retained for at least 12 months.
5. Backups and resilience
- Encrypted automated backups of customer databases (provided via Supabase).
- Backup integrity testing on a regular cadence.
- Documented disaster recovery procedures.
6. Personnel
- All personnel processing Customer Personal Data are bound by written confidentiality obligations.
- Personnel receive appropriate data protection and security awareness training.
7. Vendor and Sub-processor management
- Sub-processors are subject to written data protection contracts imposing equivalent obligations.
- Sub-processor due diligence is performed prior to engagement and reviewed periodically.
8. Incident response
- Documented Personal Data Breach response procedure.
- 48-hour notification commitment to affected customers.
- Post-incident review and remediation.
9. Physical security
- Production data is hosted in secure third-party data centres operated by the Processor's hosting Sub-processors. The Processor itself does not operate any physical data centre.
- Personnel devices are encrypted, access-controlled, and remotely manageable.
10. Data minimisation and segregation
- Customer data is logically segregated by tenant within the Platform.
- Production access to customer data is limited to personnel with a specific operational or support need.
Annex 3 — List of Sub-processors
As at the Effective Date, the Sub-processors are:
| Sub-processor | Processing function | Legal entity / location | Transfer mechanism |
|---|---|---|---|
| Vercel | Frontend application hosting | Vercel Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Supabase | Database hosting (UK/EU region) | Supabase Inc., United States (data hosted in UK/EU region) | UK IDTA / EU SCCs + UK Addendum |
| AssemblyAI | Speech-to-text transcription of call and voice audio | AssemblyAI, Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Anthropic | AI-assisted clinical documentation and summarisation (Claude API) | Anthropic Ireland Limited | UK IDTA / EU SCCs + UK Addendum where applicable |
| Retell AI | Inbound voice AI receptionist (real-time transcription, conversational AI, voice synthesis) | Retell AI, Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Twilio | SMS delivery and inbound telephony | Twilio Ireland Limited, Ireland (with possible US transit) | EU SCCs + UK Addendum |
| Resend | Transactional email delivery | Resend Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Acuity Scheduling | Appointment scheduling | Squarespace, Inc., United States | UK IDTA / EU SCCs + UK Addendum |
Note on fallback transcription engines. The Processor's transcription pipeline additionally integrates Deepgram, Inc. (United States) and OpenAI, L.L.C. (United States) as optional fallback speech-to-text engines. These are not enabled in the production configuration as at the Effective Date and do not process Customer Personal Data. If the Processor activates either as an operational Sub-processor, it will be added to this Annex and notified to the Controller under clause 5.2 before it begins processing Customer Personal Data.
Note on Stripe. Stripe Payments UK Ltd processes payment data as an independent controller, not as a Sub-processor of Seventy3, and so is not listed in this Annex. Stripe is referenced in the Privacy Policy.
