Data Processing Agreement (DPA)
Version: 1.0 · Effective date: 14 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Armada Labs Studio Ltd ("Remy", the "Processor") and the customer identified in the order or account ("Customer", the "Controller") for use of the Remy service (the "Services"), and governs the processing of Customer Personal Data. Where the DPA and the main terms conflict on data protection, this DPA prevails.
1. Definitions
"Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, and where applicable the EU GDPR, and all related regulations, as amended. "Customer Personal Data" means personal data Remy processes on the Customer's behalf under the Services. "Sub-processor" means any processor engaged by Remy. "Controller", "Processor", "Data Subject", "Personal Data Breach", "Special Category Data" and "Processing" have the meanings in Data Protection Laws. "SCCs" means the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as supplemented by the UK Addendum issued by the ICO.
2. Roles and scope
2.1 The Customer is the Controller and Remy is the Processor of Customer Personal Data. The Customer's patients and other individuals are the Data Subjects.
2.2 The subject-matter, duration, nature, purpose, types of personal data and categories of Data Subjects are set out in Annex 1.
2.3 The Customer is responsible for establishing a lawful basis (and, for Special Category Data, an Article 9 condition) for its own processing and for the instructions it gives Remy.
3. Remy's obligations as Processor
Remy shall:
(a) Process only on documented instructions from the Customer, including this DPA and use of the Services, and for no other purpose, unless required by law (in which case Remy will inform the Customer unless legally prohibited);
(b) ensure persons authorised to process Customer Personal Data are bound by confidentiality;
(c) implement the technical and organisational security measures in Annex 2 (Article 32);
(d) respect the conditions in section 5 for engaging Sub-processors;
(e) assist the Customer, by appropriate measures, in responding to Data Subject rights requests (Chapter III);
(f) assist the Customer in ensuring compliance with Articles 32–36 (security, breach notification, DPIAs and prior consultation), taking into account the information available to Remy;
(g) at the Customer's choice, delete or return all Customer Personal Data at the end of the Services and delete existing copies, unless law requires storage (see section 8);
(h) make available information necessary to demonstrate compliance and allow for and contribute to audits (see section 7); and
(i) inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Personal Data Breach
Remy shall notify the Customer without undue delay (and in any event within 48 hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably available to help the Customer meet its own notification obligations. Remy will take reasonable steps to mitigate and remediate.
5. Sub-processors
5.1 The Customer gives general authorisation for Remy to engage Sub-processors. Remy's current Sub-processors are listed at /legal/subprocessors.
5.2 Remy will give the Customer 30 days' notice (by updating that page and/or email) before adding or replacing a Sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds. If the parties can't resolve a reasonable objection, the Customer may terminate the affected Services.
5.3 Remy will impose data protection obligations on each Sub-processor no less protective than this DPA and remains liable for their performance.
6. International transfers
6.1 Remy will not transfer Customer Personal Data outside the UK/EEA except where an appropriate safeguard under Data Protection Laws is in place.
6.2 Where a transfer requires it, the parties agree the SCCs (with the UK Addendum) are incorporated by reference into this DPA, with the Customer as data exporter and Remy (or the relevant Sub-processor) as data importer, Module Two (controller-to-processor) or Module Three (processor-to-processor) applying as appropriate. Annex 1 and Annex 2 populate the corresponding SCC annexes. Onward transfers to Sub-processors are covered by equivalent clauses, including providers certified under the EU-US Data Privacy Framework where applicable.
7. Audits
Remy will make available information reasonably necessary to demonstrate compliance with this Article 28 DPA. On 30 days' written notice, no more than once a year (unless required by a supervisory authority or following a breach), the Customer may audit Remy's relevant practices, subject to confidentiality and reasonable security constraints. Remy may satisfy audit requests by providing current certifications or third-party reports where available.
8. Deletion and return
On termination or expiry of the Services, Remy will, at the Customer's election, delete or return Customer Personal Data within 90 days and delete remaining copies, except to the extent retention is required by law or for back-ups that are cycled out on Remy's standard schedule and remain protected.
9. Special Category Data
The parties acknowledge the Services involve Special Category Data (health data). Remy will apply the enhanced measures in Annex 2 to such data. The Customer confirms it has an appropriate Article 9 condition and any required Appropriate Policy Document for its processing.
10. Liability and general
Each party's liability under this DPA is subject to the limitations and exclusions in the main agreement. This DPA is governed by the law of England and Wales. It takes effect on the effective date and continues while Remy processes Customer Personal Data.
Annex 1 — Details of processing
- Subject-matter: provision of the Remy healthcare CRM Services.
- Duration: the term of the Customer's subscription, plus deletion/return period.
- Nature and purpose: hosting, storing, organising, transmitting and otherwise processing Customer Personal Data to operate CRM, scheduling, communications (email/SMS/voice), billing, and related features chosen by the Customer.
- Types of Personal Data: identifiers and contact details; appointment and clinical-administrative records; health data; communications content (incl. call recordings and transcripts); billing/payer information; staff records.
- Categories of Data Subjects: the Customer's patients, their contacts/next of kin, referrers, the Customer's staff and practitioners.
- Frequency: continuous, for the term.
Annex 2 — Technical and organisational measures (Article 32)
- Encryption of data in transit (TLS) and at rest.
- UK/EU data residency for core storage (database, files) and EU edge for telephony where available.
- Role-based and row-level access controls enforcing tenant isolation; least-privilege internal access; authentication via OAuth/SSO.
- Audit logging of access and key actions.
- Secure development, dependency and schema-change controls; environment separation.
- Regular backups with restoration testing; documented incident-response and breach-notification process.
- Sub-processor due diligence and contractual security obligations.
- Staff confidentiality undertakings and data-protection training.
- Enhanced handling for Special Category Data consistent with the above.
Annex 3 — Sub-processors
As published and maintained at /legal/subprocessors, incorporated by reference.