Legal · Template
Data Processing Agreement
A standard template setting out Alomco Ltd's obligations as data processor when your organisation is the data controller. Available as a standalone signed document alongside our Terms and Privacy Policy.
Version 1.0. Last updated: 26 August 2026. Parties: the organisation using iPCN (“the Controller”) and Alomco Ltd, company number 11746274, registered office 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom (“the Processor”). See also our Data Sharing Agreement.
1. Scope and purpose
What this covers
The Controller engages the Processor to process personal data on its behalf for the purposes of providing the iPCN platform: storing and managing staff records, leave and rota data, compliance and mandatory training records, appraisal records, recruitment data, and (where the Controller uses iPCN eSign) document e-signature data — as described in full in our Privacy Policy.
iPCN does not knowingly process patient data — it is a staff/practice-operations platform, not a clinical system.
2. Processor obligations
What Alomco Ltd commits to
The Processor shall:
- Process personal data only on the Controller's documented instructions — this Agreement, together with the Controller's use of the platform, constitutes those instructions;
- Ensure staff with access to personal data are subject to confidentiality obligations;
- Implement the technical and organisational measures set out in clause 5;
- Not engage a new sub-processor without giving the Controller 30 days' notice to object (clause 4);
- Assist the Controller in responding to data subject rights requests and in meeting its UK GDPR Articles 32–36 obligations;
- At the Controller's choice, delete or return all personal data at the end of the relationship, per clause 7;
- Make available the information reasonably necessary to demonstrate compliance with this Agreement.
3. Controller obligations
What your organisation is responsible for
The Controller shall ensure a lawful basis exists for the processing (UK GDPR Article 6), that data subjects (staff) are informed via the organisation's own privacy notice, that data entered into iPCN is accurate, and shall notify the Processor of any data subject request relevant to the processing.
4. Sub-processors
Who else processes your data
The Controller provides general written authorisation for the Processor to engage the following sub-processors, and any future replacement notified with 30 days to object:
| Sub-processor | Activity | Location |
|---|---|---|
| Neon Tech Inc. | PostgreSQL database hosting | AWS eu-west-2 (London, UK) |
| Hostinger International Ltd | Application server (VPS) hosting | EU data centre |
| Stripe, Inc. | Payment processing (paid subscriptions) | Global |
| Anthropic PBC | Alom AI assistant — receives only the chat message and the practice/user context needed to answer it, not full underlying records | US |
| Microsoft 365 | Email delivery | EU/UK |
5. Security measures
How data is protected
Technical: encryption in transit (TLS 1.2+) and at rest (AES-256 on database storage); role-based access control scoped to a member's role within their own organisation; audit logging of sensitive actions with who/when; daily encrypted database backups, retained on a rolling basis, stored off-site; logical tenant isolation preventing cross-tenant data access.
Organisational: confidentiality obligations on staff with data access; access limited to what's operationally necessary; administrative access to cross-tenant data restricted to platform administrators, with all such access logged.
6. Personal data breach
What happens if something goes wrong
The Processor shall notify the Controller without undue delay, and in any event within 24 hoursof becoming aware of a personal data breach affecting the Controller's data — including the nature of the breach, likely consequences, and remedial measures taken or proposed. The Processor shall cooperate fully with the Controller's breach response, including notifications to the ICO (UK GDPR Article 33, within 72 hours) and affected data subjects (Article 34) where required.
7. Data return and deletion
At the end of the relationship
At the Controller's choice, the Processor shall delete or return all personal data after the end of the subscription, and delete existing copies, except where UK law requires continued storage (e.g. billing records, or signed-document audit trails per our Privacy Policy).
8. International transfers
Where data is processed
Personal data is stored and processed primarily within the UK/EEA. Where a sub-processor is based outside the UK/EEA (Anthropic, Stripe), the Processor relies on an appropriate safeguard — standard contractual clauses or an adequacy decision.
9. Audit rights
Verifying compliance
The Controller may request evidence of the Processor's compliance with this Agreement (access logs, security documentation) on reasonable notice, subject to the Processor's own confidentiality obligations to other customers.
10. Term and governing law
Duration and jurisdiction
This Agreement runs for as long as the Controller has an active iPCN subscription, and is governed by the laws of England and Wales.
11. Signatories
| Data Controller (your organisation) | Data Processor (Alomco Ltd) | |
|---|---|---|
| Name | ||
| Role | ||
| Signature | ||
| Date | ||
To arrange a signed copy of this Agreement, email admin@ipcn.info.