Data Processing Agreement
Version 1.0 | Last updated: 12 August 2026
Care Governance Solutions is a product of Care Business School Ltd
Company No. 17217121 | ICO Registration No. ZC147699
This Data Processing Agreement (DPA) forms part of the agreement under which Care Business School Ltd provides the Care Governance Solutions platform to the customer. It applies where Care Business School Ltd processes personal data on behalf of the customer.
1. Parties and roles
The “Customer” is the organisation that subscribes to or otherwise contracts to use Care Governance Solutions. Care Business School Ltd, providing the Care Governance Solutions product (“CGS”), is the “Processor” where it processes Customer Personal Data on the Customer's behalf. The Customer will normally be the “Controller”. If the Customer is itself acting as a processor for another controller, CGS will act as a sub-processor and the provisions of this DPA will apply accordingly.
The Customer is responsible for determining the purposes and means of its processing, establishing an appropriate lawful basis and, where relevant, a condition for processing special category data, and ensuring that its instructions to CGS comply with Data Protection Law.
2. Definitions
| Term | Meaning |
|---|---|
| Customer Personal Data | personal data processed by CGS on behalf of the Customer through or in connection with the Care Governance Solutions service. |
| Data Protection Law | the UK GDPR, the Data Protection Act 2018, and other applicable UK laws relating to privacy and the processing of personal data, as amended from time to time. |
| Personal Data Breach | a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. |
| Sub-processor | a third party engaged by CGS to process Customer Personal Data in connection with providing the service. |
3. Scope and duration of processing
CGS will process Customer Personal Data for the duration of the Customer's subscription or other service agreement, and for any limited period afterwards where necessary to return, export, secure or delete data, comply with law, resolve disputes or enforce the agreement.
The nature and purpose of processing is to host, store, organise, retrieve, display, analyse and otherwise process Customer Personal Data as necessary to provide, secure, maintain and support the Care Governance Solutions platform and its contracted features.
4. Processing instructions
CGS will process Customer Personal Data only on documented instructions from the Customer, including the Customer's configuration and use of the platform, except where processing is required by applicable law. If CGS is legally required to process data other than on the Customer's instructions, CGS will inform the Customer before doing so unless the law prohibits that notification.
CGS will promptly inform the Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Law. CGS is not required to provide legal advice to the Customer.
5. Confidentiality
CGS will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where reasonably necessary for their role.
6. Security
CGS will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking account of the nature of the processing, the information available to CGS, the state of the art, implementation costs and the risks to individuals.
Measures may include, as appropriate to the service, authentication and access controls, role-based permissions, encryption in transit and/or at rest where supported by the relevant infrastructure, logging, secure cloud infrastructure, back-up and recovery arrangements, vulnerability and patch management, staff access controls and procedures for responding to security incidents.
The Customer remains responsible for managing its authorised users, permissions, passwords and devices, and for ensuring that only appropriate and necessary personal data is entered into the platform.
7. Special category and care-sector data
The Customer acknowledges that its use of CGS may involve information concerning staff, service users and other individuals and may include health, safeguarding or other special category personal data. The Customer controls what information it enters into the platform and must ensure that such processing is lawful, necessary and proportionate.
CGS will not independently determine the Customer's lawful basis or special category condition and will process such information only for the contracted service and in accordance with the Customer's documented instructions.
8. Sub-processors
The Customer gives CGS general written authorisation to use Sub-processors where reasonably necessary to provide and support the service. CGS will impose data protection obligations on relevant Sub-processors that provide an appropriate level of protection for the processing they perform.
CGS will maintain information about material Sub-processors used for the service and will provide reasonable notice of material changes where required by Data Protection Law or the parties' agreement. The Customer may raise a reasonable data-protection objection to a new Sub-processor. The parties will work in good faith to address the concern.
| Provider / category | Purpose |
|---|---|
| Supabase | Application database, authentication and related platform infrastructure. |
| Google Workspace | Business email and correspondence. |
| Payment provider, where used (for example Stripe) | Subscription and payment processing. |
| Hosting and technical providers used by the website or application | Hosting, security, performance and technical delivery. |
Where a listed service does not process Customer Personal Data for a particular Customer or feature, its inclusion in this list does not mean that it necessarily receives that Customer's data.
9. International transfers
CGS will ensure that any restricted transfer of Customer Personal Data for which CGS is responsible is made in accordance with applicable Data Protection Law. Where required, this may include reliance on UK adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any required transfer risk assessment/data protection test and supplementary measures.
The core Care Governance Solutions platform is configured to host customer application data in the EEA. Some supporting suppliers may process limited personal data outside the UK or EEA as part of their services, subject to applicable transfer safeguards.
10. Assistance with individual rights
Taking into account the nature of the processing, CGS will provide reasonable assistance to the Customer, through appropriate technical and organisational measures where possible, to enable the Customer to respond to requests by individuals exercising their data protection rights.
If CGS receives a request directly from an individual relating to Customer Personal Data, CGS will not respond on the Customer's behalf unless authorised or legally required to do so and will, where appropriate, direct or forward the request to the Customer.
11. Data protection impact assessments and regulatory assistance
Taking into account the nature of processing and the information available to CGS, CGS will provide reasonable assistance to the Customer with its obligations relating to security, personal data breaches, data protection impact assessments and prior consultation with the ICO where those obligations relate to CGS's processing of Customer Personal Data.
12. Personal Data Breaches
CGS will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will provide information reasonably available to CGS to help the Customer meet its legal obligations, including, where known, the nature of the incident, affected data, likely consequences and measures taken or proposed.
CGS's notification of an incident does not constitute an admission of fault or liability. The Customer remains responsible for determining whether notification to the ICO or affected individuals is required.
13. Return and deletion of data
At the end of the services, and subject to applicable law and the functionality and terms of the service, CGS will delete or return Customer Personal Data at the Customer's choice where reasonably practicable, and will delete remaining copies unless applicable law requires continued storage.
Data retained in routine backups may remain until overwritten in accordance with normal backup cycles, provided it remains protected and is not restored for active processing except where necessary for disaster recovery or legal compliance.
14. Audit and compliance information
CGS will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable to its processing under this DPA. Where reasonably required, the Customer may request additional compliance information or an audit relating to CGS's processing of Customer Personal Data.
Audits must be reasonable, proportionate, protect the confidentiality and security of CGS and other customers, and, unless required following a material incident or by a regulator, normally be conducted no more than once in any 12-month period. The parties should first seek to satisfy audit requirements through existing documentation, questionnaires, certifications or independent reports where available.
15. Customer responsibilities
- Use the platform in accordance with applicable law and the service agreement.
- Provide lawful, fair and transparent information to individuals where the Customer is the controller.
- Only collect and enter personal data that is adequate, relevant and necessary.
- Maintain appropriate access controls and promptly remove access for users who no longer require it.
- Respond to data subject requests and determine whether incidents require regulatory or individual notification.
- Maintain any records, assessments and policies required for its own compliance.
16. Liability and order of precedence
Liability arising under this DPA is subject to the limitations and exclusions of liability in the Customer's main service agreement to the extent permitted by law. Nothing in this DPA limits any rights or obligations that cannot lawfully be limited.
If there is a conflict between this DPA and the main service agreement on the processing of Customer Personal Data, this DPA will prevail to the extent of that conflict. Mandatory requirements of Data Protection Law will prevail over inconsistent contractual wording.
17. Changes to this DPA
CGS may update this DPA where reasonably necessary to reflect changes in Data Protection Law, regulatory guidance, the service or Sub-processors. Where an update materially reduces the data protection commitments applying to Customer Personal Data, CGS will provide reasonable notice.
18. Governing law
This DPA is governed by the same law and jurisdiction as the main service agreement. Where the main service agreement does not specify governing law, the laws of England and Wales apply and the courts of England and Wales have jurisdiction, subject to any mandatory rights under Data Protection Law.
Schedule 1 – Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision, operation, hosting, support, security and maintenance of the Care Governance Solutions governance and compliance platform. |
| Duration | For the term of the Customer's service and any limited post-termination retention period described in the agreement, this DPA or applicable law. |
| Nature of processing | Collection where submitted by the Customer, recording, organisation, structuring, storage, retrieval, consultation, display, analysis, generation of reports or governance outputs, transmission where instructed, restriction, deletion and other processing necessary to provide the service. |
| Purposes | To enable the Customer to manage care-sector governance and compliance activities, including policies, audits, evidence, workforce compliance, training, risk, incidents, safeguarding, complaints, health and safety, quality improvement and CQC-readiness activities, according to the features used by the Customer. |
| Categories of data subjects | Customer personnel and authorised users; applicants and workers; service users and, where entered by the Customer, relatives, representatives or contacts; complainants; witnesses; professionals; suppliers or other individuals whose information is lawfully entered into the platform. |
| Types of personal data | Names and contact details; employment and recruitment information; role and training information; DBS/Right to Work and compliance status information; user/account information; audit and governance records; incident, complaint, safeguarding and risk information; evidence and documents uploaded by the Customer; technical and security logs. |
| Special category data | May include health information and other special category data where the Customer chooses to enter it. Criminal offence data may also be processed where the Customer records lawful DBS/recruitment compliance information. The Customer determines what such data is entered and the applicable legal basis/condition. |
| Frequency | As required by the Customer's use of the platform, which may be continuous or recurring during the service term. |
Schedule 2 – Security measures
- Authentication and account access controls.
- Role-based access and permissions appropriate to the platform's configured functionality.
- Controls designed to segregate customer/tenant data.
- Encryption in transit and encryption at rest where provided by the underlying infrastructure.
- Logging and monitoring appropriate to platform security and troubleshooting.
- Back-up, recovery and service-resilience arrangements appropriate to the hosted service.
- Processes for managing security updates, vulnerabilities and access to production systems.
- Confidentiality obligations for authorised personnel.
- Incident response procedures and breach escalation.
- Periodic review and improvement of security controls in light of risk and service development.
These measures describe the intended control framework and do not constitute a representation that Care Business School Ltd holds ISO 27001 certification or any other certification unless expressly confirmed in writing.
Schedule 3 – Contact details
Processor: Care Business School Ltd, providing Care Governance Solutions
Company number: 17217121
ICO registration reference: ZC147699
Data protection / privacy contact: support@caregovernance.solutions
Customer: the legal entity identified in the applicable order form, subscription, proposal or service agreement.
Acceptance
This DPA is incorporated into the Customer's agreement for Care Governance Solutions. Where the parties sign a separate copy, the signature fields below may be used.
| Care Business School Ltd (Processor) | Customer (Controller) |
|---|---|
| Name | Name |
| Title | Title |
| Signature | Signature |
| Date | Date |