Legal

    Data Processing Agreement

    This Data Processing Agreement is incorporated by reference into the Main Agreement and governs the processing of personal data by Coherent Healthcare on behalf of its clinic customers, in compliance with the Data Protection Legislation.

    This Data Processing Agreement ("DPA") is incorporated by reference into the Main Agreement and forms part of the agreement between the following parties:

    Processor

    Coherent Healthcare Ltd ("Coherent")

    14 Hanover Square (Suite 3.12a), London, W1S 1HN
    Company No: 15067010
    ICO Registration: ZB797722

    Controller ("Clinic" or "Customer")

    The clinic or clinic group identified in the Order Form

    The clinic or clinic group identified in the Order Form entered into between the parties under Coherent's general conditions.

    Coherent and the Clinic may be referred to collectively as the "Parties" and individually as a "Party".


    Background

    (A) The Clinic has entered into an agreement with Coherent for the provision of patient engagement and booking support services (the "Main Agreement"), comprising an Order Form and Coherent's general conditions.

    (B) In delivering the Services under the Main Agreement, Coherent will process certain Personal Data on behalf of the Clinic as processor.

    (C) This DPA sets out the terms on which Coherent processes Personal Data on behalf of the Clinic as processor, in compliance with the Data Protection Legislation.

    The Parties agree to the following terms, which are incorporated into and form part of the Main Agreement.


    1. Definitions and Interpretation

    1.1. In this DPA, the following words and expressions have the meanings set out below:

    Adequate Country

    A country or territory recognised under the Data Protection Legislation as providing an adequate level of protection for Personal Data.

    Applicable Laws

    All laws, regulations, regulatory requirements and codes of practice applicable to a party's activities under this DPA.

    Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Supervisory Authority

    Have the meanings given to them in the UK GDPR.

    Data Protection Legislation

    Means, to the extent applicable: (a) the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and all related statutory codes of practice and guidance; (b) the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR); (c) the EU General Data Protection Regulation (EU) 2016/679 to the extent applicable; and (d) all other applicable laws and regulations relating to data protection and privacy in any relevant jurisdiction, as amended from time to time.

    DPIA

    A data protection impact assessment carried out in accordance with Article 35 UK GDPR.

    EU SCCs

    The Standard Contractual Clauses for the transfer of Personal Data to third countries adopted by the European Commission by Decision 2021/914 of 4 June 2021.

    IDTA or UK Addendum

    The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner's Office under section 119A of the Data Protection Act 2018, as updated from time to time.

    Main Agreement

    The Order Form and general conditions entered into between the Parties.

    Personal Data Breach

    Any accidental or unlawful loss, damage, destruction, alteration, unauthorised disclosure of, or access to, Personal Data processed by Coherent on behalf of the Clinic.

    Services

    The patient engagement and booking support services delivered by Coherent under the Clinic's brand via the Coherent Platform, as described in the Main Agreement.

    Special Category Data

    Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.

    Sub-Processor

    Any third party engaged by Coherent to process Personal Data in connection with the Services.

    Transfer Risk Assessment or TRA

    A risk assessment conducted prior to a restricted transfer of Personal Data in accordance with the ICO's guidance and the requirements of the IDTA.

    UK GDPR

    Has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.

    1.2References to legislation are to that legislation as amended, extended or re-enacted from time to time. Clause headings are for convenience only and do not affect interpretation.


    2. Scope and Application

    2.1This DPA applies to all processing of Personal Data carried out by Coherent on behalf of the Clinic in connection with the Main Agreement, and supplements the data protection provisions set out therein.

    2.2In the event of any conflict between this DPA and the Main Agreement, this DPA shall prevail to the extent of that conflict in respect of data protection matters.

    2.3The details of the processing carried out by Coherent as processor (subject matter, duration, nature, purpose, categories of data subjects and categories of Personal Data) are set out in Annex I to this DPA.


    3. Duration

    3.1This DPA shall remain in force for as long as the Main Agreement remains in force.

    3.2Clauses that by their nature are intended to survive termination (including clauses 11, 12, 13, 14 and 15) shall continue in full force and effect after the Main Agreement expires or is terminated for any reason.


    4. Governing Law and Jurisdiction

    4.1This DPA is governed by and construed in accordance with the laws of England and Wales.

    4.2Each Party irrevocably submits to the exclusive jurisdiction of the courts of England and Wales to settle any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with this DPA or its subject matter or formation.


    5. Roles of the Parties

    5.1The Parties acknowledge that, for the purposes of the Data Protection Legislation, in delivering the Services Coherent processes patient Personal Data on behalf of and in accordance with the instructions of the Clinic. In this capacity, the Clinic is the Controller and Coherent is the Processor.

    5.2This DPA governs Coherent's processing of Personal Data as Processor on behalf of the Clinic. Clauses 6 to 14 set out the respective obligations of the Parties in that regard.

    5.3Nothing in this DPA makes either Party an agent, employee or partner of the other.


    6. Clinic Obligations as Controller

    6.1The Clinic is responsible for its own compliance with the Data Protection Legislation and retains overall control of the Personal Data it provides to Coherent.

    6.2The Clinic warrants and represents that: (a) Coherent's processing of Personal Data as contemplated by this DPA and the Main Agreement will comply with the Data Protection Legislation; (b) the Clinic has and will maintain throughout the Term a valid lawful basis under Article 6 UK GDPR for each category of Personal Data shared with Coherent; (c) where the processing involves Special Category Data, the Clinic has and will maintain throughout the Term a valid condition under Article 9(2) UK GDPR for the processing of that data — the Clinic acknowledges that the most likely applicable conditions are Article 9(2)(h) (healthcare purposes, provided the processing is carried out by or under the responsibility of a healthcare professional) and Article 9(2)(a) (explicit consent of the data subject), and the Clinic is solely responsible for determining which condition applies and for maintaining its validity; (d) all patient Personal Data shared with Coherent is accurate, complete and up to date; (e) the Clinic has provided all required privacy notices to data subjects and has obtained all consents required by applicable data protection law (including, where applicable, under Data Protection Legislation, the CAN-SPAM Act and CASL) before sharing patient Personal Data with Coherent; (f) the processing instructions given to Coherent under this DPA and the Main Agreement are lawful; and (g) the Clinic's employees will not use the Services in a manner that is unlawful or harmful.

    6.3The Clinic will promptly notify Coherent of any change to its lawful basis, Article 9(2) condition or any applicable consent in relation to patient Personal Data, and will cooperate in good faith with Coherent to address any consequences of that change for the delivery of the Services.


    7. Coherent's Obligations as Processor

    Processing on Instructions

    7.1Coherent will process Personal Data only in accordance with the Clinic's documented instructions, unless required to do so by Applicable Laws. If Applicable Laws require Coherent to process Personal Data in a manner inconsistent with the Clinic's instructions, Coherent will inform the Clinic before processing (unless prohibited from doing so by law). Coherent will promptly notify the Clinic if, in its reasonable opinion, any instruction infringes the Data Protection Legislation.

    Purpose Limitation

    7.2Coherent will not process Personal Data for any purpose other than as set out in Annex I and as otherwise agreed in writing by the Parties.

    Confidentiality

    7.3Coherent will maintain the confidentiality of all Personal Data and will not disclose it to any third party unless the Clinic or this DPA specifically authorises the disclosure, or disclosure is required by Applicable Laws. Coherent will ensure that all personnel authorised to process Personal Data are subject to enforceable confidentiality obligations.

    Personnel

    7.4Coherent will ensure that access to Personal Data is strictly limited to those personnel who need access to the relevant data in order to deliver the Services. All such personnel will: (a) be informed of the confidential nature of the Personal Data; (b) have completed appropriate data protection and information security training on commencement of their role and periodically thereafter; (c) be subject to user authentication and access logging when accessing Personal Data; and (d) be required to comply with all applicable obligations under this DPA.

    Security Measures

    7.5Coherent will implement and maintain appropriate technical and organisational measures against unauthorised or unlawful processing, access, copying, modification, reproduction, display or distribution of Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Personal Data. These measures are set out in full in Annex II to this DPA.

    Assistance with Compliance

    7.6Coherent will provide reasonable assistance to the Clinic (at the Clinic's cost) in: (a) responding to data subject rights requests (including access, rectification, erasure, restriction, portability and objection); (b) conducting DPIAs where required under Article 35 UK GDPR; (c) prior consultations with the ICO or other relevant Supervisory Authority where a DPIA indicates a high risk; and (d) meeting any other obligations of the Clinic under the Data Protection Legislation in relation to which Coherent's assistance is reasonably required.

    Records of Processing

    7.7Coherent will maintain records of its processing activities in accordance with Article 30(2) UK GDPR and will make those records available to the Clinic or the ICO on request.


    8. Data Subject Rights

    8.1Coherent will notify the Clinic without undue delay, and in any event within 48 hours of receipt, if it receives any complaint, notice, communication or request from a data subject in relation to the processing of Personal Data under this DPA.

    8.2Coherent will not respond to any data subject rights request directly (save as required by law) without the Clinic's prior written consent, but will promptly provide the Clinic with all cooperation, information and access reasonably required to enable the Clinic to respond within applicable statutory timescales.

    8.3Coherent will assist the Clinic in complying with data subject rights under the Data Protection Legislation, including subject access requests, rights to rectification, erasure, restriction, portability and objection, and will provide the Clinic with any Personal Data it holds in relation to a data subject on request.


    9. Personal Data Breaches

    Notification

    9.1Coherent will notify the Clinic without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach. Notification will include, to the extent then available: (a) a description of the nature of the breach, including the categories and approximate number of data subjects and Personal Data records affected; (b) the name and contact details of Coherent's data protection contact; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

    Investigation and Cooperation

    9.2Coherent will, following a Personal Data Breach: (a) use reasonable endeavours to contain and mitigate the breach; (b) cooperate fully with the Clinic in the investigation; (c) make relevant records, logs and data available to the Clinic; and (d) facilitate access to facilities and interviews with relevant personnel.

    Notifications to Third Parties

    9.3Coherent will not notify any data subject, the ICO or any other regulator of a Personal Data Breach without the Clinic's prior written consent, except where required to do so by Applicable Laws. The Clinic has the sole right to determine: (a) whether to provide notice to data subjects, the ICO or any other body; (b) the contents and method of any notice; and (c) whether to offer any remedy to affected data subjects.


    10. Audit Rights

    10.1Coherent will permit the Clinic and its authorised third-party representatives to audit Coherent's compliance with this DPA on not less than 30 days' prior written notice and no more than once in any 12 month period, save that this frequency limit shall not apply where a Personal Data Breach has occurred or where Coherent is in material breach of its obligations under this DPA. This may include: (a) remote or physical access to records and information relating to the processing of Personal Data; (b) meetings with relevant Coherent personnel; and (c) inspection of relevant systems, facilities and infrastructure.

    10.2The Clinic will use its reasonable endeavours to conduct audits during business hours and in a manner that minimises disruption to Coherent's operations. The costs of any audit requested by the Clinic will be borne by the Clinic unless the audit reveals a material breach by Coherent.


    11. Sub-Processors

    General Authorisation

    11.1The Clinic gives Coherent general written authorisation to engage third-party Sub-Processors for the processing of Personal Data in connection with the Services, subject to compliance with this clause 11. The Sub-Processors currently approved are set out in Annex III to this DPA.

    Notification of Changes

    11.2Coherent will notify the Clinic in writing, on not less than 14 days' prior written notice, of any intended addition or replacement of Sub-Processors. The Clinic may object to the proposed change by written notice to Coherent within 7 days of receiving Coherent's notification, provided that the objection is based on reasonable, documented data protection grounds.

    Objection Process

    11.3If the Clinic objects to a proposed Sub-Processor change on reasonable data protection grounds, the Parties will cooperate in good faith to resolve the objection. If the objection cannot be resolved and Coherent proceeds with the Sub-Processor change, the Clinic may, as its sole remedy, terminate the Main Agreement and this DPA on written notice without penalty. Coherent's obligation to notify under clause 11.2 is a proactive obligation; it is not satisfied by the Clinic checking a list.

    Sub-Processor Obligations

    11.4Coherent will impose data protection obligations on all Sub-Processors that are equivalent to those imposed on Coherent under this DPA. Coherent will carry out appropriate due diligence on each Sub-Processor before engagement.

    Liability

    11.5Coherent remains fully liable to the Clinic for the acts and omissions of its Sub-Processors to the same extent as if Coherent had performed the processing directly.


    12. International Transfers

    12.1Coherent will not transfer Personal Data outside the United Kingdom without ensuring that an appropriate international transfer mechanism is in place in accordance with the Data Protection Legislation.

    12.2Where the Clinic is established outside the United Kingdom, the following provisions apply: (a) the Clinic is responsible for identifying whether the transfer of Personal Data from the Clinic to Coherent constitutes a restricted transfer under the data protection law applicable in its jurisdiction, and for ensuring that a lawful transfer mechanism is in place before any such transfer commences — the parties will cooperate in good faith to put in place such additional transfer agreements as may be necessary to ensure the lawfulness of the transfer before processing commences; and (b) where Coherent transfers Personal Data from the United Kingdom back to a Clinic established outside the United Kingdom (or to any other non-Adequate Country in connection with the Services), the EU SCCs (Module 4: Processor to Controller) supplemented by the UK IDTA will apply, or such other mechanism as the Parties agree in writing, and must be put in place before any such return transfer takes place.

    12.3Coherent will not transfer Personal Data to any Sub-Processor located outside the United Kingdom or the EEA unless an appropriate international transfer mechanism is in place in accordance with the Data Protection Legislation before that transfer takes place.


    13. Deletion and Return of Personal Data

    13.1On termination or expiry of the Main Agreement (or on the Clinic's written request during the Term), Coherent will, at the Clinic's election, either: (a) securely delete or destroy all Personal Data in its possession or control; or (b) return all Personal Data to the Clinic in a commonly used machine-readable format.

    13.2Coherent will complete the deletion or return under clause 13.1 within 30 days of the relevant trigger event and will provide written certification to the Clinic confirming that all copies have been deleted (or returned, as applicable).

    13.3Coherent may retain Personal Data beyond the 30-day period to the extent, and for so long as, required by Applicable Laws. Any such retained data will continue to be processed in accordance with this DPA and will be deleted as soon as the legal retention requirement ceases to apply.


    14. Clinics Located Outside the UK

    14.1Where a Clinic is established or operates in a jurisdiction outside the United Kingdom, the following provisions apply: (a) the Clinic warrants that it complies with all applicable local data protection and health data laws in its jurisdiction, including (where applicable) the Health Insurance Portability and Accountability Act 1996 (HIPAA) and applicable US state privacy laws, and the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian provincial privacy laws; and (b) where the Clinic is located in the USA, the Parties will work in good faith to put in place a Business Associate Agreement between them for the processing of patient health information.


    15. Liability

    15.1The liability provisions of the Main Agreement apply equally to claims arising under this DPA.

    15.2Subject to clause 15.1, each Party will be responsible for and will indemnify the other against any regulatory fines, penalties or enforcement action imposed by any Supervisory Authority or other local data protection regulator to the extent attributable to that Party's breach of its obligations under this DPA or the Data Protection Legislation.


    16. General

    16.1This DPA together with Annexes I, II and III constitutes the entire agreement between the Parties in relation to the processing of Personal Data under the Main Agreement and supersedes all prior arrangements, representations and understandings on that subject matter.

    16.2Coherent may update this DPA at any time to reflect changes in the Data Protection Legislation or ICO guidance.

    16.3No failure or delay by either Party in exercising any right or remedy under this DPA will constitute a waiver of that right or remedy.

    16.4If any provision of this DPA is found to be invalid or unenforceable, it will be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions will continue in full force.

    16.5This DPA shall be binding on and enure for the benefit of the Parties and their respective successors and permitted assigns.


    Annex I: Details of Processing

    This Annex forms part of the DPA and sets out the details of the processing carried out by Coherent as Processor on behalf of the Clinic.

    Subject matter of processing

    The provision of patient engagement and booking support services on behalf of the Clinic under the Clinic's brand, including patient recall, appointment scheduling and rebooking, patient outreach, booking payments and related administrative support.

    Duration of processing

    For the duration of the Main Agreement, and thereafter as required by Applicable Laws or to fulfil the obligations under clause 13 of this DPA.

    Nature and purpose of processing

    The following categories of processing are carried out under this DPA: (a) Patient Engagement: contacting patients of the Clinic (by SMS, email, WhatsApp and telephone) on behalf of and under the brand of the Clinic, for the purposes of appointment recall, rebooking, scheduling and patient retention. (b) Know Your Customer (KYC) and Onboarding: verifying the identity of the Clinic and its authorised contacts as required by applicable financial and regulatory requirements. (c) Service Delivery: collection, storage, use and disclosure of Personal Data as necessary to deliver the Services in accordance with the Clinic's instructions, including access to the Clinic's Practice Management Software ("PMS") where required. (d) Communications Infrastructure: transmission of messages and communications via third-party providers (including Twilio for SMS and Meta for WhatsApp) on the Clinic's instructions. (e) Payment Facilitation: Coherent processes payments on behalf of the Clinic, and processes the personal data of the Data Subjects as requested by the Clinic in order to send payment links and aid payment reconciliation.

    Categories of data subjects

    Patients of the Clinic; Clinic staff and directors, to the extent their data is provided in connection with the Agreement.

    Categories of personal data

    Names and contact details (phone number, email address, postal address); date of birth; appointment history and service type; information arising through patient communications; payment details to the extent accessible through the Clinic's PMS.

    Special category personal data

    Special Category Data within the meaning of Article 9 UK GDPR may be processed where a patient volunteers health information in the course of communications with Coherent (for example, disclosing a medical condition, disability or treatment history). The Clinic is solely responsible for ensuring it has a valid condition under Article 9(2) UK GDPR before sharing Special Category Data with Coherent (see clause 6.2(c)).

    Frequency of transfer

    Ongoing for the duration of the Main Agreement, as required for the delivery of the Services.

    Period of retention

    For the duration of the Main Agreement, and thereafter in accordance with clause 13 of this DPA.


    Annex II: Technical and Organisational Security Measures

    Coherent implements and maintains the following technical and organisational security measures in accordance with clause 7.5 of this DPA:

    (a) Encryption

    All Personal Data is encrypted in transit using TLS and at rest using industry-standard encryption protocols.

    (b) Access Controls

    Role-based access controls (RBAC) are in place to ensure that only authorised personnel have access to Personal Data, limited to what is necessary for their role. Access rights are reviewed regularly and revoked promptly on change of role or departure.

    (c) Staff Vetting and Training

    All personnel with access to Personal Data are subject to appropriate pre-employment screening and are required to complete data protection and information security training on joining and periodically thereafter. All personnel are bound by confidentiality obligations.

    (d) Audit Logging

    Access to and processing of Personal Data is logged, and those logs are retained and reviewed periodically to detect unauthorised access or anomalous activity.

    (e) Network and System Security

    Coherent maintains firewalls, intrusion detection systems and up-to-date antivirus and anti-malware software across its systems. Security patches and updates are applied promptly.

    (f) Incident Response

    Coherent maintains a documented incident response procedure, including procedures for identifying, containing, investigating and notifying Personal Data Breaches in accordance with clause 9 of this DPA.

    (g) Business Continuity and Resilience

    Coherent maintains backup and recovery procedures to ensure the availability and resilience of its processing systems and the ability to restore access to Personal Data in a timely manner following an incident.

    (h) Supplier and Sub-Processor Security

    Coherent requires all Sub-Processors to maintain equivalent technical and organisational measures and conducts appropriate due diligence before engaging any Sub-Processor.

    (i) Data Minimisation

    Coherent collects and processes only Personal Data that is necessary for the delivery of the Services and does not retain Personal Data beyond the period specified in Annex I.


    Annex III: Approved Sub-Processors

    The following Sub-Processors are approved as at the date of this DPA. Coherent will update this Annex in accordance with clause 11.2 of this DPA.

    Adyen NV

    Reason

    Adyen facilitates payment services for Coherent's Customers.

    Data transferred

    Name, credit card and bank account information, to allow the Customer to accept payments from their clients.

    Country

    The Netherlands

    Transfer mechanism

    Adequacy Decision under the EU GDPR

    Amazon Web Services (AWS)

    Reason

    AWS hosts Coherent's cloud infrastructure, including the servers that receive and store personal data.

    Data transferred

    All categories of personal data listed in the Schedule.

    Country

    United Kingdom

    Transfer mechanism

    N/A

    Anthropic

    Reason

    Anthropic provides models that power Coherent's AI-assisted patient engagement features.

    Data transferred

    Name, contact details, appointment information, and clinical notes which may contain health data.

    Country

    United States

    Transfer mechanism

    EU Standard Contractual Clauses (Module Three: Processor-to-Processor), as supplemented by the UK International Data Transfer Addendum.

    Twilio Inc.

    Reason

    Twilio provides text and email communications services, used to send payment links, reminders and patient-engagement messages to the Customer's clients.

    Data transferred

    Name, phone number, email address, appointment information, and message content which may contain health data.

    Country

    United States

    Transfer mechanism

    UK Extension to the EU–U.S. Data Privacy Framework (under Twilio Inc.'s certification), supplemented by EU Standard Contractual Clauses (Module Three: Processor-to-Processor) and the UK International Data Transfer Addendum.

    Meta Platforms Ireland LimitedEngaged only where enabled

    Engaged only where the Customer authorises Coherent to engage patients on their behalf via WhatsApp, or where the Customer chooses to process new enquiries originating from Meta platforms.

    Reason

    Provides the WhatsApp Business Cloud API for patient messaging, and Meta lead/enquiry capture, where the Customer has enabled these channels.

    Data transferred

    Name, phone number, appointment information, message content which may contain health data, and enquiry/lead details submitted via Meta platforms.

    Country

    Ireland (Meta Platforms Ireland Limited), with onward transfer to the United States

    Transfer mechanism

    Transfer to Meta Platforms Ireland Limited (Dublin, Ireland) under UK adequacy regulations for the EEA; onward transfer to the United States is made by Meta under its EU–US Data Privacy Framework certification.

    Slack Technologies, LLC (a Salesforce company)

    Reason

    Slack delivers internal operational notifications to Coherent staff, which may reference patient or Customer personal data.

    Data transferred

    Operational alert data, which may include a Data Subject's personal information.

    Country

    United States

    Transfer mechanism

    UK Extension to the EU–U.S. Data Privacy Framework (under Salesforce, Inc.'s certification, which covers Slack Technologies, LLC), supplemented by EU Standard Contractual Clauses (Module Three: Processor-to-Processor) and the UK International Data Transfer Addendum.