WealHeal.Back to home
TRUST & TRANSPARENCY

Data processing agreement

Pre-launch drafts · Updated 9 October 2026

Company details and legal review are outstanding. These pages do not certify legal or clinical compliance.

Instructions and scope

This draft requires signed customer terms before it forms an agreement. The provider is controller and the intended WealHeal UK Limited is processor. Subject matter: provision of a care-operations workspace. Duration: customer contract plus agreed exit/retention period. Data subjects: service users, relatives, staff and authorised contacts. Data: identity, contact, care, health, safeguarding, supervision and access records.

Article 28 obligations

The final agreement must require documented lawful instructions, confidentiality, appropriate Article 32 measures, assistance with rights requests, security incidents, DPIAs and regulator enquiries; deletion or return at contract end unless law requires retention; evidence and proportionate audit rights; and notification where an instruction infringes applicable data-protection law.

Subprocessors and transfers

A verified subprocessor schedule, change-notification mechanism, authorisation process and equivalent written obligations must be supplied. Ireland database hosting is confirmed in the app; other delivery, email, support and future AI services require separate assessment. Appropriate transfer safeguards must cover onward processing outside adequate destinations.

Security, breach and deletion schedule

Organisation-scoped access controls, authenticated requests and care-write audit events are implemented foundations. Independent security assurance, enforced MFA, server-side inactivity, backup retention, restore testing, incident-response timings and erasure procedures need verification before being contracted. The processor must inform the controller without undue delay on becoming aware of a personal-data breach; the controller assesses any applicable 72-hour regulator notification requirement.