The Article 28 UK GDPR agreement we enter into with every customer organisation, published in full.
This Agreement is made between:
Report Rx Ltd, a company registered in England and Wales with company number 17359078, whose registered office is at Imperial House, 79–81 Hornby Street, Bury, BL9 5BN ("ReportRx", "we", "us", the "Processor"); and
the Customer named in the signature block of the executed copy (the "Customer", the "Controller").
This Agreement forms part of, and is subject to, the services agreement between the parties for the supply of the ReportRx platform (the "Principal Agreement"). Where this Agreement conflicts with the Principal Agreement on matters of data protection, this Agreement prevails.
"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any other applicable law relating to the processing of personal data, as amended or replaced from time to time.
"UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
"Personal Data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR.
"Customer Personal Data" means the Personal Data described in Annex 1 that ReportRx processes on behalf of the Customer under the Principal Agreement.
"Services" means the ReportRx clinical activity tracking and reporting platform supplied under the Principal Agreement.
"Sub-processor" means any third party engaged by ReportRx to process Customer Personal Data.
3.1 The Customer is the controller of Customer Personal Data and ReportRx is the processor. Each party will comply with its own obligations under the Data Protection Legislation.
3.2 The Customer is responsible for ensuring it has a lawful basis for the processing it instructs, for the accuracy of the data it enters, and for providing any privacy information required to its own staff.
3.3 ReportRx is a controller only in respect of data it processes for its own business purposes, such as contract administration and billing contacts. That processing is governed by the ReportRx privacy policy, not by this Agreement.
4.1 The Services are designed to record clinical activity as counts and categories against defined workstreams. The platform is not a clinical record system.
4.2 The Customer must not enter, upload or otherwise submit patient-identifiable information into the Services. This includes patient names, NHS numbers, dates of birth, addresses, contact details, clinical notes, diagnoses and prescribing records.
4.3 The parties acknowledge that, on this basis, the processing under this Agreement does not involve special category data relating to patients, nor confidential patient information as understood under the common law duty of confidentiality. Section 251 support is not required and the National Data Opt-Out does not apply.
4.4 If the Customer becomes aware that patient-identifiable information has been entered into the Services, it must notify ReportRx without undue delay so the parties can agree its secure removal.
ReportRx will:
(a) process Customer Personal Data only on the Customer's documented instructions, including the instructions set out in this Agreement and the Principal Agreement, unless required to do otherwise by law, in which case ReportRx will inform the Customer of that legal requirement before processing unless the law prohibits it;
(b) ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidence;
(c) implement and maintain the technical and organisational measures described in Annex 2;
(d) engage Sub-processors only in accordance with clause 7;
(e) taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under Chapter III of the UK GDPR;
(f) assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of the processing and the information available to ReportRx;
(g) at the Customer's choice, delete or return Customer Personal Data at the end of the Services in accordance with clause 10; and
(h) make available to the Customer all information necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits in accordance with clause 11.
ReportRx will immediately inform the Customer if, in its opinion, an instruction infringes the Data Protection Legislation.
6.1 ReportRx will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2.
6.2 ReportRx will not use Customer Personal Data for its own purposes, will not sell it, and will not use it to train machine learning models.
7.1 The Customer gives ReportRx general authorisation to engage the Sub-processors listed in Annex 3.
7.2 ReportRx will give the Customer at least 30 days' written notice before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the Principal Agreement in respect of the affected Services without penalty.
7.3 ReportRx will impose on each Sub-processor data protection obligations no less protective than those in this Agreement, and remains fully liable to the Customer for the performance of each Sub-processor.
8.1 Customer Personal Data is stored in the European Union (Ireland) and processed by servers in the United Kingdom (London). No Customer Personal Data is stored or processed outside the United Kingdom or the European Economic Area.
8.2 Ireland benefits from UK adequacy regulations, so no additional transfer safeguards are required for storage in that country.
8.3 ReportRx will not transfer Customer Personal Data to a country outside the United Kingdom that is not subject to UK adequacy regulations unless it has put in place the UK International Data Transfer Addendum, the International Data Transfer Agreement, or another lawful transfer mechanism, and has notified the Customer.
9.1 ReportRx will notify the Customer without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting Customer Personal Data.
9.2 The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
9.3 ReportRx will cooperate with the Customer and take such reasonable steps as the Customer directs to assist in the investigation, mitigation and remediation of the breach, so that the Customer can meet its own obligations to the Information Commissioner and to data subjects.
9.4 ReportRx will not notify any supervisory authority or data subject of a breach affecting Customer Personal Data on the Customer's behalf without the Customer's prior written instruction, unless required to do so by law.
10.1 On termination or expiry of the Principal Agreement, ReportRx will, at the Customer's written election, return Customer Personal Data in a structured, commonly used, machine-readable format, or delete it.
10.2 Unless the Customer elects otherwise, ReportRx will delete Customer Personal Data, including from backups in line with its backup rotation, within 90 days of termination.
10.3 ReportRx may retain Customer Personal Data to the extent required by law, in which case it will continue to protect it in accordance with this Agreement and will process it only for the purpose requiring retention.
11.1 ReportRx will make available to the Customer, on reasonable written request and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, the information necessary to demonstrate compliance with this Agreement.
11.2 ReportRx will contribute to audits and inspections conducted by the Customer or an auditor appointed by the Customer, subject to reasonable notice, confidentiality undertakings, and conduct that minimises disruption to ReportRx's business and to other customers.
12.1 The limitations and exclusions of liability set out in the Principal Agreement apply to this Agreement, except where the Data Protection Legislation prohibits their application.
12.2 This Agreement takes effect on the date of the last signature and continues for as long as ReportRx processes Customer Personal Data.
12.3 This Agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.
| Item | Detail |
|---|---|
| Subject matter | Provision of the ReportRx clinical activity tracking and reporting platform. |
| Duration | The term of the Principal Agreement, plus the deletion period in clause 10. |
| Nature and purpose | Recording clinical activity, tracking completeness, producing reports, and supporting the Customer's governance and assurance needs. Hosting, storage, backup, access control and support. |
| Categories of data subject | The Customer's staff and workers who use or are recorded in the Services — clinicians, managers and administrators. |
| Types of personal data | Name; work email address; job role; organisational unit (practice, neighbourhood team, PCN or other); activity records comprising counts and categories of clinical activity with dates; authentication and audit records including sign-in events and records of who entered or amended data. |
| Special category data | None. The Services do not process special category data. |
| Patient data | None. See clause 4. |
| Frequency | Continuous for the term of the Principal Agreement. |
ReportRx maintains the following measures. They may be updated from time to time provided the level of security is not reduced.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | European Union (Ireland) |
| Vercel | Application hosting and content delivery | United Kingdom (London) |
| Resend | Transactional email, including sign-in codes and notifications | European Union |
| Google Workspace | Business email and calendar | United Kingdom / European Union |
ReportRx will give notice of changes to this list in accordance with clause 7.2.
For a signable copy, a completed supplier assurance questionnaire, or any question about this Agreement, contact hello@reportrx.co.uk.
Report Rx Ltd
Imperial House
79–81 Hornby Street
Bury
BL9 5BN
Company number 17359078