Legal · Template

Data Processing Agreement

A standard template setting out Alomco Ltd's obligations as data processor when your organisation is the data controller. Available as a standalone signed document alongside our Terms and Privacy Policy.

Version 1.0. Last updated: 26 August 2026. Parties: the organisation using iPCN (“the Controller”) and Alomco Ltd, company number 11746274, registered office 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom (“the Processor”). See also our Data Sharing Agreement.

1. Scope and purpose

What this covers

The Controller engages the Processor to process personal data on its behalf for the purposes of providing the iPCN platform: storing and managing staff records, leave and rota data, compliance and mandatory training records, appraisal records, recruitment data, and (where the Controller uses iPCN eSign) document e-signature data — as described in full in our Privacy Policy.

iPCN does not knowingly process patient data — it is a staff/practice-operations platform, not a clinical system.

2. Processor obligations

What Alomco Ltd commits to

The Processor shall:

  • Process personal data only on the Controller's documented instructions — this Agreement, together with the Controller's use of the platform, constitutes those instructions;
  • Ensure staff with access to personal data are subject to confidentiality obligations;
  • Implement the technical and organisational measures set out in clause 5;
  • Not engage a new sub-processor without giving the Controller 30 days' notice to object (clause 4);
  • Assist the Controller in responding to data subject rights requests and in meeting its UK GDPR Articles 32–36 obligations;
  • At the Controller's choice, delete or return all personal data at the end of the relationship, per clause 7;
  • Make available the information reasonably necessary to demonstrate compliance with this Agreement.

3. Controller obligations

What your organisation is responsible for

The Controller shall ensure a lawful basis exists for the processing (UK GDPR Article 6), that data subjects (staff) are informed via the organisation's own privacy notice, that data entered into iPCN is accurate, and shall notify the Processor of any data subject request relevant to the processing.

4. Sub-processors

Who else processes your data

The Controller provides general written authorisation for the Processor to engage the following sub-processors, and any future replacement notified with 30 days to object:

Sub-processorActivityLocation
Neon Tech Inc.PostgreSQL database hostingAWS eu-west-2 (London, UK)
Hostinger International LtdApplication server (VPS) hostingEU data centre
Stripe, Inc.Payment processing (paid subscriptions)Global
Anthropic PBCAlom AI assistant — receives only the chat message and the practice/user context needed to answer it, not full underlying recordsUS
Microsoft 365Email deliveryEU/UK

5. Security measures

How data is protected

Technical: encryption in transit (TLS 1.2+) and at rest (AES-256 on database storage); role-based access control scoped to a member's role within their own organisation; audit logging of sensitive actions with who/when; daily encrypted database backups, retained on a rolling basis, stored off-site; logical tenant isolation preventing cross-tenant data access.

Organisational: confidentiality obligations on staff with data access; access limited to what's operationally necessary; administrative access to cross-tenant data restricted to platform administrators, with all such access logged.

6. Personal data breach

What happens if something goes wrong

The Processor shall notify the Controller without undue delay, and in any event within 24 hoursof becoming aware of a personal data breach affecting the Controller's data — including the nature of the breach, likely consequences, and remedial measures taken or proposed. The Processor shall cooperate fully with the Controller's breach response, including notifications to the ICO (UK GDPR Article 33, within 72 hours) and affected data subjects (Article 34) where required.

7. Data return and deletion

At the end of the relationship

At the Controller's choice, the Processor shall delete or return all personal data after the end of the subscription, and delete existing copies, except where UK law requires continued storage (e.g. billing records, or signed-document audit trails per our Privacy Policy).

8. International transfers

Where data is processed

Personal data is stored and processed primarily within the UK/EEA. Where a sub-processor is based outside the UK/EEA (Anthropic, Stripe), the Processor relies on an appropriate safeguard — standard contractual clauses or an adequacy decision.

9. Audit rights

Verifying compliance

The Controller may request evidence of the Processor's compliance with this Agreement (access logs, security documentation) on reasonable notice, subject to the Processor's own confidentiality obligations to other customers.

10. Term and governing law

Duration and jurisdiction

This Agreement runs for as long as the Controller has an active iPCN subscription, and is governed by the laws of England and Wales.

11. Signatories

Data Controller (your organisation)Data Processor (Alomco Ltd)
Name  
Role  
Signature  
Date  
Email  

To arrange a signed copy of this Agreement, email admin@ipcn.info.