ReportRxClinical activity tracking
NHS governance Dashboard Completeness The report
Clinician log in Book a demo
Report Rx Ltd

Data Processing Agreement

The Article 28 UK GDPR agreement we enter into with every customer organisation, published in full.

Version 1.0 · Last updated 13 September 2026

What this is

  • The data processing agreement we enter into with every customer, made under Article 28 of the UK GDPR.
  • It is published here so you can review it during evaluation. A signable copy is provided with every contract.
  • Key point: ReportRx holds no patient-identifiable data — see clause 4.
Download the signable version

1. The parties

This Agreement is made between:

Report Rx Ltd, a company registered in England and Wales with company number 17359078, whose registered office is at Imperial House, 79–81 Hornby Street, Bury, BL9 5BN ("ReportRx", "we", "us", the "Processor"); and

the Customer named in the signature block of the executed copy (the "Customer", the "Controller").

This Agreement forms part of, and is subject to, the services agreement between the parties for the supply of the ReportRx platform (the "Principal Agreement"). Where this Agreement conflicts with the Principal Agreement on matters of data protection, this Agreement prevails.

2. Definitions

"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any other applicable law relating to the processing of personal data, as amended or replaced from time to time.

"UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.

"Personal Data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR.

"Customer Personal Data" means the Personal Data described in Annex 1 that ReportRx processes on behalf of the Customer under the Principal Agreement.

"Services" means the ReportRx clinical activity tracking and reporting platform supplied under the Principal Agreement.

"Sub-processor" means any third party engaged by ReportRx to process Customer Personal Data.

3. Roles of the parties

3.1  The Customer is the controller of Customer Personal Data and ReportRx is the processor. Each party will comply with its own obligations under the Data Protection Legislation.

3.2  The Customer is responsible for ensuring it has a lawful basis for the processing it instructs, for the accuracy of the data it enters, and for providing any privacy information required to its own staff.

3.3  ReportRx is a controller only in respect of data it processes for its own business purposes, such as contract administration and billing contacts. That processing is governed by the ReportRx privacy policy, not by this Agreement.

4. No patient-identifiable data

4.1  The Services are designed to record clinical activity as counts and categories against defined workstreams. The platform is not a clinical record system.

4.2  The Customer must not enter, upload or otherwise submit patient-identifiable information into the Services. This includes patient names, NHS numbers, dates of birth, addresses, contact details, clinical notes, diagnoses and prescribing records.

4.3  The parties acknowledge that, on this basis, the processing under this Agreement does not involve special category data relating to patients, nor confidential patient information as understood under the common law duty of confidentiality. Section 251 support is not required and the National Data Opt-Out does not apply.

4.4  If the Customer becomes aware that patient-identifiable information has been entered into the Services, it must notify ReportRx without undue delay so the parties can agree its secure removal.

5. ReportRx's obligations as processor

ReportRx will:

(a)  process Customer Personal Data only on the Customer's documented instructions, including the instructions set out in this Agreement and the Principal Agreement, unless required to do otherwise by law, in which case ReportRx will inform the Customer of that legal requirement before processing unless the law prohibits it;

(b)  ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidence;

(c)  implement and maintain the technical and organisational measures described in Annex 2;

(d)  engage Sub-processors only in accordance with clause 7;

(e)  taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under Chapter III of the UK GDPR;

(f)  assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of the processing and the information available to ReportRx;

(g)  at the Customer's choice, delete or return Customer Personal Data at the end of the Services in accordance with clause 10; and

(h)  make available to the Customer all information necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits in accordance with clause 11.

ReportRx will immediately inform the Customer if, in its opinion, an instruction infringes the Data Protection Legislation.

6. Security

6.1  ReportRx will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2.

6.2  ReportRx will not use Customer Personal Data for its own purposes, will not sell it, and will not use it to train machine learning models.

7. Sub-processors

7.1  The Customer gives ReportRx general authorisation to engage the Sub-processors listed in Annex 3.

7.2  ReportRx will give the Customer at least 30 days' written notice before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the Principal Agreement in respect of the affected Services without penalty.

7.3  ReportRx will impose on each Sub-processor data protection obligations no less protective than those in this Agreement, and remains fully liable to the Customer for the performance of each Sub-processor.

8. International transfers

8.1  Customer Personal Data is stored in the European Union (Ireland) and processed by servers in the United Kingdom (London). No Customer Personal Data is stored or processed outside the United Kingdom or the European Economic Area.

8.2  Ireland benefits from UK adequacy regulations, so no additional transfer safeguards are required for storage in that country.

8.3  ReportRx will not transfer Customer Personal Data to a country outside the United Kingdom that is not subject to UK adequacy regulations unless it has put in place the UK International Data Transfer Addendum, the International Data Transfer Agreement, or another lawful transfer mechanism, and has notified the Customer.

9. Personal data breaches

9.1  ReportRx will notify the Customer without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting Customer Personal Data.

9.2  The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.

9.3  ReportRx will cooperate with the Customer and take such reasonable steps as the Customer directs to assist in the investigation, mitigation and remediation of the breach, so that the Customer can meet its own obligations to the Information Commissioner and to data subjects.

9.4  ReportRx will not notify any supervisory authority or data subject of a breach affecting Customer Personal Data on the Customer's behalf without the Customer's prior written instruction, unless required to do so by law.

10. Return and deletion

10.1  On termination or expiry of the Principal Agreement, ReportRx will, at the Customer's written election, return Customer Personal Data in a structured, commonly used, machine-readable format, or delete it.

10.2  Unless the Customer elects otherwise, ReportRx will delete Customer Personal Data, including from backups in line with its backup rotation, within 90 days of termination.

10.3  ReportRx may retain Customer Personal Data to the extent required by law, in which case it will continue to protect it in accordance with this Agreement and will process it only for the purpose requiring retention.

11. Audit

11.1  ReportRx will make available to the Customer, on reasonable written request and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, the information necessary to demonstrate compliance with this Agreement.

11.2  ReportRx will contribute to audits and inspections conducted by the Customer or an auditor appointed by the Customer, subject to reasonable notice, confidentiality undertakings, and conduct that minimises disruption to ReportRx's business and to other customers.

12. Liability and term

12.1  The limitations and exclusions of liability set out in the Principal Agreement apply to this Agreement, except where the Data Protection Legislation prohibits their application.

12.2  This Agreement takes effect on the date of the last signature and continues for as long as ReportRx processes Customer Personal Data.

12.3  This Agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.

Annex 1 — Details of the processing

ItemDetail
Subject matterProvision of the ReportRx clinical activity tracking and reporting platform.
DurationThe term of the Principal Agreement, plus the deletion period in clause 10.
Nature and purposeRecording clinical activity, tracking completeness, producing reports, and supporting the Customer's governance and assurance needs. Hosting, storage, backup, access control and support.
Categories of data subjectThe Customer's staff and workers who use or are recorded in the Services — clinicians, managers and administrators.
Types of personal dataName; work email address; job role; organisational unit (practice, neighbourhood team, PCN or other); activity records comprising counts and categories of clinical activity with dates; authentication and audit records including sign-in events and records of who entered or amended data.
Special category dataNone. The Services do not process special category data.
Patient dataNone. See clause 4.
FrequencyContinuous for the term of the Principal Agreement.

Annex 2 — Technical and organisational measures

ReportRx maintains the following measures. They may be updated from time to time provided the level of security is not reduced.

Access control

  • Row-level security enforced at the database layer, so a user can retrieve only data belonging to their own organisation.
  • Role-based permissions determining what each user can see and do within their organisation.
  • Multi-factor authentication available on user accounts and required on administrative and infrastructure accounts.
  • Invite-based access with no self-registration; the Customer controls who has access and may revoke it at any time.
  • Least-privilege access for ReportRx personnel, reviewed periodically. Access to Customer Personal Data is limited to what is necessary to support the Services and is logged.

Technical measures

  • Encryption in transit using TLS 1.2 or above.
  • Encryption at rest using AES-256.
  • Automated daily backups with point-in-time recovery.
  • Audit logging of authentication events and data changes.
  • Dependency and vulnerability monitoring, with security patches applied promptly.
  • Separation of development, staging and production environments. Production data is not used in development.

Organisational measures

  • Confidentiality obligations binding all personnel with access to Customer Personal Data.
  • Documented incident response process covering detection, notification and remediation.
  • Written agreements with all Sub-processors imposing equivalent data protection obligations.
  • Periodic review of access rights and security configuration.

Annex 3 — Authorised sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication and file storageEuropean Union (Ireland)
VercelApplication hosting and content deliveryUnited Kingdom (London)
ResendTransactional email, including sign-in codes and notificationsEuropean Union
Google WorkspaceBusiness email and calendarUnited Kingdom / European Union

ReportRx will give notice of changes to this list in accordance with clause 7.2.

Contact

For a signable copy, a completed supplier assurance questionnaire, or any question about this Agreement, contact hello@reportrx.co.uk.

Report Rx Ltd
Imperial House
79–81 Hornby Street
Bury
BL9 5BN
Company number 17359078

ReportRxClinical activity tracking

Clinical activity tracking and productivity reporting for clinical teams across primary and community care.

Product
The dashboard The report How it works Sign in
Company
Report Rx Ltd Company no. 17359078 Imperial House
79–81 Hornby Street
Bury
BL9 5BN
Contact
hello@reportrx.co.uk Book a demo
© 2026 ReportRx. All rights reserved. Privacy policy · Terms · Data protection · DPA