1.1 This Data Processing Agreement ("DPA") forms part of the Service Agreement between:
Data Controller: [Care Home / Organisation Name] ("Controller")
Data Processor: CareKudos Ltd ("Processor")
1.2 This DPA reflects the parties' agreement regarding the processing of personal data in compliance with UK GDPR and the Data Protection Act 2018.
1.3 CareKudos Ltd is registered with the Information Commissioner's Office (ICO). Registration Reference: ZC108498.
1.4 In the event of any conflict between this DPA and the main Service Agreement, this DPA shall prevail.
2.1 In this DPA:
"Data Protection Legislation" means the UK GDPR and Data Protection Act 2018.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on personal data.
"Data Subject" means the individual to whom personal data relates.
"Sub-processor" means a third party engaged by the Processor.
"Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
"Service Agreement" means the agreement between the Controller and the Processor for the provision of the Platform services.
"Platform" means the CareKudos software, website, and mobile applications.
3.1.1 This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller.
3.1.2 The subject matter, duration, nature, and purpose of the Processing are set out in Appendix 1.
3.1.3 The categories of Data Subjects and types of Personal Data are set out in Appendix 1.
3.2.1 The Controller determines the purposes and means of Processing.
3.2.2 The Processor Processes Personal Data only on documented instructions from the Controller.
4.1 The Processor shall:
4.1.1 Process Personal Data only on documented instructions.
4.1.2 Ensure persons authorised to process have committed to confidentiality.
4.1.3 Implement appropriate technical and organisational measures (Appendix 2).
4.1.4 Not engage another Sub-processor without authorisation (Section 8).
4.1.5 Assist the Controller in responding to Data Subject rights requests.
4.1.6 Assist with compliance with Data Protection Legislation.
4.1.7 Return or delete Personal Data at the end of services (Section 13).
4.1.8 Make available all information necessary to demonstrate compliance.
4.1.9 Notify the Controller of any Data Breach without undue delay (Section 10).
5.1 The Processor shall Process Personal Data only:
5.1.1 For the purpose of providing the Platform services.
5.1.2 In accordance with the Controller's documented instructions.
5.1.3 As required to comply with applicable law.
5.2 The Controller instructs the Processor to Process Personal Data for:
5.2.1 User account management.
5.2.2 Platform operation and maintenance.
5.2.3 Recognition and posting features.
5.2.4 Report generation (including CQC evidence).
5.2.5 Support services.
5.2.6 Values and culture tracking.
5.2.7 Notification delivery.
5.3 The Processor shall notify the Controller if, in its opinion, an instruction infringes Data Protection Legislation.
6.1 The Processor shall ensure that all personnel authorised to process Personal Data are subject to confidentiality obligations.
6.2 Confidentiality obligations survive termination of employment or engagement.
6.3 Access to Personal Data is granted only to personnel who need it to perform their duties.
7.1 The Processor shall implement the technical and organisational measures set out in Appendix 2.
7.2 The Controller acknowledges that security requirements evolve and agrees that the measures may be updated provided they do not reduce overall security.
7.3 The Processor shall maintain a record of all security updates and changes.
8.1 The Controller authorises engagement of the following Sub-processors:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting | UK / EEA |
| SendGrid | Email delivery | UK / EEA |
| Twilio | SMS notifications | UK / EEA |
| GoCardless | Direct Debit payment processing | UK / EEA |
| Google Analytics | Usage analytics (anonymised) | UK / EEA |
8.2 The Processor shall:
8.2.1 Impose data protection obligations on Sub-processors.
8.2.2 Remain fully liable for Sub-processor performance.
8.2.3 Notify the Controller of any intended changes with 30 days' notice.
8.2.4 Maintain a current list of all Sub-processors.
8.2.5 Ensure all Sub-processors comply with UK GDPR.
9.1 The Processor shall assist the Controller by:
9.1.1 Providing functionality for Data Subjects to access their data.
9.1.2 Responding to Controller requests regarding Data Subject rights.
9.1.3 Implementing technical measures to facilitate rights.
9.2 If a Data Subject contacts the Processor directly, the Processor shall:
9.2.1 Not disclose any information without Controller authorisation.
9.2.2 Advise the Data Subject to contact the Controller.
9.2.3 Notify the Controller of the request.
9.3 The Processor shall not respond to any Data Subject request without the Controller's prior written authorisation.
10.1 In the event of a Data Breach, the Processor shall:
10.1.1 Notify the Controller without undue delay and in any event within 24 hours of becoming aware.
10.1.2 Provide all available information about the breach.
10.1.3 Take steps to mitigate effects.
10.1.4 Cooperate with investigation and remediation.
10.2 Notification shall include:
10.2.1 Nature of the breach.
10.2.2 Categories and approximate number of Data Subjects affected.
10.2.3 Likely consequences.
10.2.4 Measures taken or proposed.
10.3 The Processor shall maintain a record of all Data Breaches.
11.1 The Processor shall assist the Controller with Data Protection Impact Assessments.
11.2 Assistance includes providing relevant information about the Processor's Processing activities.
11.3 The Processor shall provide reasonable cooperation with any regulatory consultation.
12.1 Personal Data is primarily processed within the UK / European Economic Area (EEA).
12.2 If transfers outside the UK/EEA are necessary, the Processor shall ensure appropriate safeguards.
12.3 Current Sub-processors may involve data transfers to the US under Standard Contractual Clauses.
12.4 The Processor shall inform the Controller of any new international data transfers.
13.1 Upon termination of services, the Processor shall:
13.1.1 Provide the Controller with access to export data for 30 days.
13.1.2 After 30 days, securely delete all Personal Data.
13.1.3 Provide written confirmation of deletion.
13.2 The Processor may retain data as required by law.
13.3 The Processor shall ensure that all copies of Personal Data are deleted or returned.
14.1 The Controller may audit the Processor's compliance by:
14.1.1 Reviewing provided documentation and certifications.
14.1.2 Requesting additional information.
14.1.3 Conducting an on-site audit with reasonable notice (maximum once per year).
14.2 The Processor may charge a reasonable fee for extensive audits (maximum once per year).
14.3 The Processor shall contribute to regulatory audits as required.
14.4 The Controller shall not have access to other customers' data during an audit.
15.1 Liability under this DPA is subject to the limitations in the main Service Agreement.
15.2 The parties agree that the Controller may pursue remedies under the Service Agreement for any breach of this DPA.
15.3 The Processor's total liability under this DPA shall not exceed the total Fees paid by the Controller in the preceding 12 months.
16.1 This DPA continues in effect until termination of the Service Agreement.
16.2 The obligations under Sections 6 (Confidentiality), 13 (Return and Deletion), and 14 (Audit Rights) survive termination.
The provision of a staff recognition and culture intelligence platform for care settings.
The duration of the Service Agreement plus the retention period thereafter.
This DPA forms part of, and should be read together with, the CareKudos Service Agreement. For questions about this DPA, contact privacy@carekudos.co.uk.
We use cookies to run the site and, with your consent, to understand how it is used. Choose which categories to allow. See our Cookie Policy for details.
Required for the site to function, such as security and remembering your choices. These cannot be switched off.