Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between Dealsparrow Limited, trading as NeuroClo (“Processor”, “NeuroClo”, “we”, or “us”), and the customer entity that has entered into Terms of Service, an order form, or another written services agreement with NeuroClo for the NeuroClo platform (“Controller”, “Customer”, or “you”).
This DPA applies where NeuroClo processes Personal Data on behalf of Customer in connection with the Services. It is intended to meet Article 28 of the UK GDPR and Article 28 of the EU GDPR. A separate Business Associate Agreement (“BAA”) is required where HIPAA applies to Protected Health Information; this DPA does not replace a BAA.
1. Definitions
In this DPA:
- Applicable Data Protection Law means UK GDPR, the Data Protection Act 2018, EU GDPR, and any other data protection or privacy law applicable to the processing of Customer Personal Data under the Agreement (excluding, unless expressly stated, U.S. HIPAA, which is addressed in a BAA where applicable).
- Agreement means the Terms of Service, order form, master services agreement, or other written contract under which NeuroClo provides the Services to Customer.
- Customer Personal Data means Personal Data processed by NeuroClo on behalf of Customer in providing the Services, including patient and clinical data where applicable.
- EU GDPR means Regulation (EU) 2016/679.
- UK GDPR means the UK General Data Protection Regulation as retained and amended in UK law.
- Personal Data, Data Subject, Processing, Controller, Processor, Supervisory Authority, and Personal Data Breach have the meanings given in Applicable Data Protection Law.
- Services means the NeuroClo healthcare technology platform and related services described in the Agreement (excluding NeuroClo’s public marketing website activities where NeuroClo acts as an independent controller).
- Standard Contractual Clauses or SCCs means the European Commission Standard Contractual Clauses for international transfers, and/or the UK International Data Transfer Agreement or UK Addendum, as applicable.
- Subprocessor means any processor engaged by NeuroClo to process Customer Personal Data.
Terms used but not defined in this DPA have the meanings in the Agreement or Privacy Policy as context requires.
2. Roles of the parties
For Customer Personal Data processed in the Services:
- Customer is the Controller (or, where Customer is itself a processor for a third-party controller, Customer warrants it is authorised to instruct NeuroClo); and
- NeuroClo is the Processor.
NeuroClo will process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement, this DPA, product configuration, and support tickets, unless Applicable Data Protection Law requires otherwise (in which case NeuroClo will inform Customer before processing, unless prohibited by law).
Customer is responsible for:
- the lawfulness of its instructions;
- identifying a lawful basis (and any Article 9 condition) for processing special category data / health data;
- providing required notices to Data Subjects;
- obtaining consents or authorisations where required (including for recording features); and
- ensuring Authorised Users use the Services in accordance with Applicable Data Protection Law.
Patients’ care relationship remains with Customer (or the relevant Healthcare Provider), not NeuroClo, consistent with the Privacy Policy and Terms of Service.
3. Details of processing
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are set out in Annex I.
4. Processor obligations
NeuroClo shall:
- (a) process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers, unless required by law as above;
- (b) ensure persons authorised to process Customer Personal Data are bound by confidentiality obligations;
- (c) implement appropriate technical and organisational measures as described in Annex II and Article 32 UK/EU GDPR;
- (d) comply with the Subprocessor conditions in Section 5;
- (e) taking into account the nature of processing, assist Customer by appropriate technical and organisational measures, insofar as possible, with Data Subject rights requests under Applicable Data Protection Law;
- (f) assist Customer in ensuring compliance with Articles 32 to 36 UK/EU GDPR (security, breach notification, DPIAs, and prior consultation), taking into account the nature of processing and information available to NeuroClo;
- (g) at Customer’s choice, delete or return Customer Personal Data after the end of the provision of Services relating to processing, and delete existing copies unless law requires storage (see Section 10);
- (h) make available to Customer information necessary to demonstrate compliance with Article 28 UK/EU GDPR and allow for and contribute to audits as described in Section 8; and
- (i) immediately inform Customer if, in NeuroClo’s opinion, an instruction infringes Applicable Data Protection Law.
5. Subprocessors
Customer authorises NeuroClo to engage Subprocessors to process Customer Personal Data. A current list of Subprocessors is set out in Annex III (or available on request / a designated webpage). Customer provides general authorisation for those Subprocessors.
NeuroClo will impose data-protection obligations on Subprocessors that are substantially no less protective than those in this DPA, including regarding security and confidentiality. NeuroClo remains liable to Customer for the Subprocessor’s performance of its data-protection obligations under this DPA, to the extent required by Applicable Data Protection Law.
NeuroClo will give Customer prior notice of intended additions or replacements of Subprocessors (email or in-product notice is sufficient), and Customer may object on reasonable data-protection grounds within fifteen (15) days. If Customer objects and the parties cannot resolve the objection, Customer may terminate the affected Services as its sole remedy (with a pro-rata refund of prepaid unused fees for the terminated portion, where applicable).
6. International transfers
Customer Personal Data may be transferred to and processed in countries outside the United Kingdom and European Economic Area, including the United States, where Amazon Web Services and other Subprocessors operate.
Where a transfer requires a transfer mechanism under Applicable Data Protection Law, the parties rely on:
- adequacy decisions;
- the EU SCCs (Module 2: Controller to Processor, or Module 3 where Customer is a processor), completed as reasonably required;
- the UK IDTA and/or UK Addendum to the EU SCCs; and/or
- other lawful transfer mechanisms.
The SCCs / UK transfer tools are incorporated by reference where required. For EU SCCs Module 2: Customer is data exporter and NeuroClo is data importer, unless the parties agree otherwise in writing. Annex details are as set out in Annexes I–III of this DPA. Where SCCs conflict with this DPA on transfer matters, the SCCs prevail.
NeuroClo will not transfer Customer Personal Data to a third country in a manner that breaches Applicable Data Protection Law.
7. Security
NeuroClo implements and maintains the technical and organisational measures in Annex II, designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. Measures are reviewed and updated as appropriate for risk, technology, and legal requirements.
Customer is responsible for securely managing Authorised User credentials, configuring access within the Services, and using the Services in a secure manner.
8. Audits and information
Upon written request, NeuroClo will provide information reasonably necessary for Customer to demonstrate compliance with Article 28, including relevant security summaries, certifications (if available), and audit reports under NDA.
If Customer reasonably requires an on-site or further audit, the parties will agree scope, timing, and confidentiality in advance. Audits are limited to once per twelve (12) months unless a Personal Data Breach or regulatory requirement justifies more frequent audit. Customer bears its own costs; NeuroClo may charge reasonable costs for time and resources beyond providing standard documentation, except where an audit reveals material non-compliance with this DPA caused by NeuroClo.
Audits must not unreasonably interfere with NeuroClo’s business or compromise security or confidentiality of other customers’ data. Remote audits and review of third-party audit reports are preferred.
9. Personal Data Breaches
NeuroClo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to NeuroClo to help Customer meet its notification obligations under Applicable Data Protection Law.
Notification will describe, where known: the nature of the breach; categories and approximate numbers of Data Subjects and records; likely consequences; and measures taken or proposed. NeuroClo may provide information in phases as it becomes available.
NeuroClo will reasonably cooperate with Customer’s investigation and remediation. NeuroClo’s notification is not an admission of fault or liability.
10. Return and deletion
Upon termination or expiry of the Services (or earlier upon written request, subject to technical feasibility and legal retention), NeuroClo will, at Customer’s choice, return Customer Personal Data in a reasonable common format or delete it from active systems, and delete remaining copies within a commercially reasonable period, except:
- data in backups, which will be overwritten in the ordinary backup cycle;
- data NeuroClo must retain under Applicable Data Protection Law or other law; and
- data retained as required for security, dispute resolution, or enforcement, limited to what is necessary and protected as under this DPA.
Retention of healthcare information may also follow Customer instructions and regulatory requirements as described in the Privacy Policy.
11. Data Subject requests and third-party requests
If NeuroClo receives a Data Subject request relating to Customer Personal Data, NeuroClo will, where the Data Subject is identifiable as Customer’s patient or user, direct the individual to Customer and/or promptly notify Customer, and will not respond substantively except on Customer’s instructions or as required by law (consistent with the Privacy Policy).
If NeuroClo receives a legal demand for Customer Personal Data, NeuroClo will, to the extent legally permitted, notify Customer before disclosure so Customer may seek a protective order or other remedy, unless notification is prohibited.
12. AI-assisted features
Where Customer enables AI-assisted features (including transcription, clinical note assistance, summarisation, or related tools):
- NeuroClo and its Subprocessors process Customer Personal Data to deliver those features on Customer’s instructions;
- AI-generated output is assistive only and does not replace clinical judgement;
- Customer Personal Data and Customer Content are not used to train publicly available AI models unless expressly authorised by the Customer in writing; and
- Customer remains responsible for reviewing AI-generated content before clinical use.
13. HIPAA and other healthcare laws
Where Customer is a HIPAA Covered Entity or Business Associate and PHI will be processed, the parties will enter a separate BAA. In the event of conflict between this DPA and a BAA regarding PHI, the BAA controls for HIPAA matters; this DPA controls for UK/EU GDPR processor obligations regarding the same data to the extent both apply.
Customer remains responsible for compliance with applicable healthcare privacy and professional obligations in its jurisdiction (including UK/EU health data rules and U.S. state laws).
14. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except that nothing excludes liability that cannot be limited under Applicable Data Protection Law. For clarity, regulatory fines imposed on one party are not automatically recoverable from the other except to the extent caused by that other party’s breach of this DPA or Applicable Data Protection Law and permitted by the Agreement and mandatory law.
15. Term
This DPA takes effect on the Effective Date above (or the date Customer first uses the Services that involve processing Customer Personal Data, if later) and continues until NeuroClo ceases processing Customer Personal Data under the Agreement.
16. Governing law and hierarchy
This DPA is governed by the governing law of the Agreement (generally the laws of England and Wales). If the Agreement is silent, this DPA is governed by the laws of England and Wales.
Order of precedence for data-protection conflicts: (1) SCCs / UK transfer tools (for transfer matters); (2) BAA (for HIPAA/PHI matters); (3) this DPA; (4) the Agreement; (5) the Privacy Policy.
17. Contact
Data protection enquiries regarding this DPA:
- Email: hello@neuroclo.com
- Dealsparrow Limited, 395 Clapham Road, London, SW9 9BT, United Kingdom
- Company Number: 07415063
Annex I — Details of processing
A. Subject matter and duration
Processing of Customer Personal Data to provide, maintain, secure, support, and improve the Services as described in the Agreement, for the duration of the Agreement plus any post-termination retention/deletion period in Section 10.
B. Nature and purpose
Hosting, storage, transmission, display, backup, support, security monitoring, analytics necessary to operate the Services, communications features, scheduling and clinical workflow tools, optional AI-assisted documentation features, and related processing on Customer’s instructions.
C. Types of Personal Data
Depending on Services configured by Customer, may include:
- identity and contact data (names, emails, phone numbers, account identifiers);
- professional / employment data (job title, clinic affiliation);
- patient demographics and contact details;
- appointment and scheduling data;
- health and clinical data (assessments, treatment records, notes, referrals, insurance/coverage information);
- audio/video recordings and transcriptions where features are enabled;
- billing-related information; and
- usage, device, log, and security data generated through use of the Services.
Special category data / health data may be included where Customer uses the Services for healthcare purposes.
D. Categories of Data Subjects
- Customer’s personnel and Authorised Users;
- patients and service users of Customer;
- patients’ family members, carers, or emergency contacts where provided; and
- other individuals whose data Customer chooses to upload or process through the Services.
E. Frequency of transfer (for SCCs)
Continuous / as needed to provide the Services.
F. Retention
As set out in Section 10, Customer instructions, and Applicable Data Protection Law.
Annex II — Technical and organisational measures
NeuroClo maintains a risk-based security programme that may include, as appropriate to the Services:
- encryption in transit;
- encryption at rest;
- role-based and least-privilege access controls;
- authentication controls for Authorised Users (including support for strong authentication where offered);
- audit logging and security monitoring;
- backup and recovery procedures;
- infrastructure security controls (including cloud provider controls under Subprocessor agreements);
- vulnerability management;
- workforce confidentiality and access controls;
- secure development and change-management practices; and
- incident response processes.
Further detail may be provided in security documentation under NDA. Measures are designed to protect Personal Data; no system can guarantee absolute security.
Annex III — Subprocessors
A current customer-facing list is published at Subprocessors. The table below summarises core Subprocessors that may process Customer Personal Data (subject to change under Section 5 and the published list). NeuroClo may use various AWS services to provide the platform; the specific services used may change over time as the Services evolve.
| Subprocessor | Purpose | Typical location(s) |
|---|---|---|
| Amazon Web Services, Inc. (“AWS”) and affiliates | Cloud hosting and infrastructure; databases and storage; authentication and identity; encryption and key management; email and communications; telehealth and messaging; AI-assisted transcription and clinical documentation; logging, monitoring, backup, and security services | AWS regions configured for the Services |
| Payment / billing providers (as configured) | Subscription billing and payment processing for Customer accounts | As configured by provider |
| Customer support / productivity tools (as used for support) | Support ticketing and related assistance (access to Customer Personal Data only as needed for support) | As configured by provider |
Marketing-website analytics providers (such as Google Analytics or Vercel Analytics) process data in NeuroClo’s capacity as controller for the marketing site and are outside the scope of this DPA unless they process Customer Personal Data within the Services.
← Back to NeuroClo