Data Processing Agreement
Last updated: [date]
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and [Legal Entity Name], trading as Mogpharm(“Processor”), for the provision of the Mogpharm Service. It governs the processing of personal data by the Processor on behalf of the Controller under the UK GDPR and the Data Protection Act 2018.
1. Roles
The Controller determines the purposes and means of processing the pharmacy data it uploads (including staff and operational records). The Processor processes that data only to provide the Service. Where the Processor processes account/website data for its own purposes, it acts as an independent controller under its Privacy Policy.
2. Scope of processing
- Subject matter: provision of the Mogpharm compliance platform.
- Duration: the term of the agreement, plus any retention period.
- Nature & purpose: hosting, storing, and processing pharmacy governance data so the Controller can manage compliance and inspection readiness.
- Types of personal data: names, work contact details, roles; operational records; and any personal data the Controller chooses to enter (e.g. incident details).
- Categories of data subjects: the Controller’s staff and other individuals referenced in its records.
3. Processor obligations
- Process personal data only on the Controller’s documented instructions (including this DPA and use of the Service).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Section 6).
- Engage sub-processors only as set out in Section 5 and impose equivalent obligations on them.
- Assist the Controller, taking into account the nature of processing, with data-subject requests and with its obligations on security, breach notification and impact assessments.
- Notify the Controller without undue delay after becoming aware of a personal-data breach.
- At the Controller’s choice, delete or return personal data at the end of the agreement, subject to legal retention requirements.
- Make available information necessary to demonstrate compliance and allow for reasonable audits.
4. Controller obligations
The Controller warrants that it has a lawful basis to provide the personal data to the Processor and to instruct the processing described here, and that its instructions comply with data-protection law.
5. Sub-processors
The Controller authorises the Processor to engage the sub-processors below. We will give reasonable notice of any intended change and give the Controller the opportunity to object on reasonable data-protection grounds.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | United Kingdom (London) |
| Vercel | Application hosting & content delivery | Global edge; [confirm function region] |
| Resend | Transactional & notification email | [confirm region] |
6. Security measures
- Tenant isolation enforced by database row-level security.
- Encryption of data in transit (TLS) and at rest.
- Role-based, least-privilege access controls and audit logging of administrative actions.
- Separation of production, staging and demonstration environments.
- Regular backups and access restricted to authorised personnel. [Backup/restore cadence to be confirmed.]
7. International transfers
Primary storage is in the United Kingdom (London). Where a sub-processor processes personal data outside the UK, transfers are made under appropriate safeguards (such as the UK International Data Transfer Agreement/Addendum). [Confirm per-sub-processor regions above.]
8. Retention and deletion
Personal data is retained for the term and for any period required by law or the Service (for example, controlled-drug and governance records). On termination, data is deleted or returned per the Controller’s instruction, subject to those requirements.
9. General
This DPA is governed by the law of [England and Wales]. In the event of conflict with the main agreement on data-protection matters, this DPA prevails. Contact: [privacy@mogpharm.com].