Data Processing Agreement
Controller – processor terms effective 15 September 2026
This Data Processing Agreement forms part of the Agreement between Aspirium and the Customer. It applies whenever Aspirium processes Controller Personal Data on the Customer’s behalf in providing the Services.
1. Parties and status
1.1 Parties This Data Processing Agreement (DPA) is between Aspirium Ltd, a company registered in England and Wales under company number 16989063, whose registered office is 23 The Mead, Ashton Keynes, Swindon, England, SN6 6PL (Aspirium, we, us or Processor), and the customer identified in the applicable Order (Customer, you or Controller). Aspirium Ltd is registered with the Information Commissioner’s Office as a data controller. ICO registration number: ZC245198.
1.2 Relationship to the Agreement This DPA supplements the Aspirium Terms of Service, the applicable Order and any service schedule (together, the Agreement). It is incorporated into the Agreement without a separate signature when the Customer orders or uses a Service involving processing to which this DPA applies.
1.3 Roles For Controller Personal Data, the Customer is the controller and Aspirium is the processor, unless the processing particulars state otherwise. Each party will comply with Data Protection Law in relation to its own activities. Aspirium remains an independent controller for account, billing, fraud-prevention and business-contact data that it determines how and why to process, as described in its Privacy Policy.
1.4 Priority If this DPA conflicts with another part of the Agreement about the protection or processing of Controller Personal Data, this DPA prevails. An expressly agreed service-specific data protection schedule prevails over this DPA to the extent of a conflict.
2. Definitions and interpretation
2.1 Data Protection Law Data Protection Law means all data protection and privacy law applicable to the processing under the Agreement, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003, in each case as amended or replaced.
2.2 Defined terms Controller Personal Data means personal data processed by Aspirium on the Customer’s behalf under the Agreement. UK GDPR has the meaning given in section 3(10), as supplemented by section 205(4), of the Data Protection Act 2018. Applicable terms including controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meanings given by Data Protection Law.
2.3 Schedules Schedule 1 describes the processing. Schedule 2 describes the minimum technical and organisational measures. Schedule 3 records the initial authorisation for subprocessors and the mechanism for service-specific suppliers.
3. Scope and Customer instructions
3.1 Documented instructions Aspirium will process Controller Personal Data only on the Customer’s documented instructions, including those contained in the Agreement, the Customer’s use and configuration of the Services, and written directions from an authorised contact, unless UK law requires otherwise.
3.2 Legal requirement If law requires processing beyond the Customer’s instructions, Aspirium will inform the Customer of that legal requirement before processing unless the law prohibits the information on important grounds of public interest.
3.3 Unlawful instruction Aspirium will notify the Customer if, in its reasonable opinion, an instruction infringes Data Protection Law. Aspirium may suspend the affected processing until the parties agree a lawful approach. Aspirium is not required to provide legal advice or independently determine the Customer’s compliance.
3.4 Customer control The Customer determines what Controller Personal Data is placed in the Services and is responsible for configuring access, retention and other Customer-controlled settings. Aspirium may process technical metadata, logs and copies reasonably necessary to secure, troubleshoot, restore and support the Services as part of the Customer’s instructions.
4. Customer obligations
4.1 Lawfulness and transparency The Customer warrants that its instructions and the collection, disclosure and processing of Controller Personal Data comply with Data Protection Law. The Customer will establish a lawful basis, provide required privacy information, respond to data subjects and obtain any consent or authorisation required for Aspirium and authorised subprocessors to process the data.
4.2 Data minimisation The Customer will provide only Controller Personal Data that is adequate, relevant and limited to what is necessary for the Services, keep it accurate where required, and avoid retaining it longer than necessary.
4.3 Sensitive data The Customer must not use a Service for special-category data, patient-identifiable information or criminal-offence data unless the Service is suitable for that processing, the Order or service schedule permits it, and the Customer has implemented appropriate legal, contractual, access and security safeguards.
4.4 AI restriction The Customer must not submit patient-identifiable information, special-category data, criminal-offence data, passwords, payment-card data or other highly confidential information to an artificial-intelligence feature unless a written Order or service schedule expressly authorises that data and records the applicable safeguards and instructions.
4.5 Security responsibilities The Customer will protect credentials, use appropriate permissions and multi-factor authentication where available, maintain Customer-controlled devices and software, and promptly notify Aspirium of suspected compromise. The Customer is responsible for assessing whether the Services and stated security measures are appropriate for its processing risks.
5. Aspirium personnel and confidentiality
5.1 Access limitation Aspirium will restrict access to Controller Personal Data to personnel and contractors who need it to provide, secure or support the Services.
5.2 Confidentiality Aspirium will ensure that persons authorised to process Controller Personal Data are subject to an appropriate duty of confidentiality and receive relevant data protection and security guidance.
5.3 Compliance Aspirium will take reasonable steps to ensure that authorised persons process Controller Personal Data only as permitted by this DPA and the Agreement.
6. Security
6.1 Measures Taking account of the state of the art, implementation costs, and the nature, scope, context and purposes of processing and risks to individuals, Aspirium will implement and maintain appropriate technical and organisational measures designed to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, that data.
6.2 Schedule 2 The measures in Schedule 2 are the baseline measures applicable to the Services. They may be updated to reflect technical development and supplier changes, provided the overall level of protection is not materially reduced during the term.
6.3 Shared responsibility The measures depend on the Service selected and do not replace Customer-controlled security. The Customer acknowledges that no internet-connected system can be guaranteed completely secure and will follow reasonable security advice and maintain independent copies of important data where appropriate.
7. Personal data breaches
7.1 Notification Aspirium will notify the Customer without undue delay after becoming aware of a personal data breach affecting Controller Personal Data. Notification does not constitute an admission of fault or liability.
7.2 Information To the extent known and reasonably available, the notification will describe the nature of the breach, affected data and individuals, likely consequences, measures taken or proposed, and a contact point for further information. Aspirium may provide information in phases as the investigation develops.
7.3 Response Aspirium will take reasonable steps to contain, investigate, mitigate and remediate the breach and will provide reasonable cooperation to help the Customer meet applicable notification duties. The Customer is responsible for deciding whether and how to notify the ICO, another authority, data subjects or third parties.
8. Data subject rights and regulatory assistance
8.1 Requests Taking account of the nature of the processing, Aspirium will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests to exercise data subject rights. If Aspirium receives a request relating to Controller Personal Data, it will direct the person to the Customer where practicable and will not respond substantively unless authorised or legally required.
8.2 Compliance assistance Taking account of the nature of processing and information available to Aspirium, Aspirium will provide reasonable assistance with the Customer’s obligations concerning security, breach assessment and notification, data protection impact assessments and prior consultation with a supervisory authority.
8.3 Costs Standard assistance available through Service functionality or ordinary support is included in the fees. Aspirium may charge reasonable fees for substantial, repetitive or bespoke assistance, taking account of the work involved, unless the assistance is required because Aspirium breached this DPA. Aspirium will inform the Customer of expected charges in advance where practicable.
9. Subprocessors
9.1 General authorisation The Customer gives Aspirium general written authorisation to appoint subprocessors to process Controller Personal Data for the Services. The initial authorisation is described in Schedule 3.
9.2 Equivalent protection Before a subprocessor processes Controller Personal Data, Aspirium will enter into a written contract requiring data protection obligations that provide materially equivalent protection to the obligations imposed on Aspirium by this DPA, to the extent applicable to the subprocessor’s services.
9.3 Responsibility Aspirium remains responsible to the Customer for the performance of its subprocessors’ data protection obligations as required by Data Protection Law.
9.4 Changes Aspirium will give reasonable prior notice of an intended addition or replacement of a subprocessor by email, client-area notice, a maintained subprocessor page or other written communication. The Customer must keep its contact details current and review such notices.
9.5 Objection The Customer may object on reasonable data protection grounds by giving detailed written reasons before the stated change date. The parties will work in good faith to resolve the objection, which may include a reasonable configuration change, an alternative supplier where commercially practicable, or termination of the affected Service. If no reasonable solution is available, either party may terminate the affected Service on written notice; Aspirium will refund prepaid fees for unused complete months. The Customer may not object solely to obtain a commercial advantage or avoid agreed fees.
10. International transfers
10.1 Locations Controller Personal Data may be processed in the United Kingdom and in other countries in which an authorised subprocessor operates or provides support. Hosting data location will be the region selected or stated for the Service, subject to technical copies, support access and the arrangements described in the Agreement.
10.2 Restricted transfers Aspirium will not make a restricted transfer of Controller Personal Data unless permitted by Data Protection Law, including through UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary measures where required.
10.3 Information On reasonable request, Aspirium will provide information available to it about the relevant transfer mechanism, subject to confidentiality and third-party restrictions.
11. Return and deletion
11.1 During the term The Customer may retrieve or delete Controller Personal Data using available Service functionality. Export formats, tools and assistance depend on the Service. Bespoke export or migration assistance may be chargeable.
11.2 End of Services On termination or expiry of the affected Service, Aspirium will, at the Customer’s choice and subject to available functionality, return or delete Controller Personal Data and delete existing copies, unless UK law requires storage. The Customer must communicate its choice and complete any export before the Service ends.
11.3 Operational copies Deletion from active systems may not immediately remove data from resilient backups, logs or supplier systems. Remaining copies will be isolated from ordinary use, protected and deleted or overwritten under applicable retention cycles, unless law requires longer retention. Aspirium does not guarantee post-termination recovery.
12. Information and audits
12.1 Information Aspirium will make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, which may include this DPA, security descriptions, supplier information, questionnaires, policies, summaries or independent reports where available.
12.2 Audit process Where that information is insufficient, the Customer may conduct or appoint an independent auditor to conduct a proportionate audit relating to Controller Personal Data. Except following a material breach or where a supervisory authority requires otherwise, audits are limited to once in any 12-month period, during normal business hours, on at least 30 days’ written notice, and must avoid unreasonable disruption and risks to other customers or systems.
12.3 Safeguards and cost An auditor must not be a competitor of Aspirium and must sign appropriate confidentiality terms. Aspirium may satisfy an audit request using relevant third-party assurance and may restrict access to information that would compromise security or another person’s rights. The Customer bears its audit costs and Aspirium’s reasonable assistance costs unless the audit identifies a material breach by Aspirium.
12.4 Regulators Aspirium will cooperate with a competent supervisory authority as required by Data Protection Law.
13. Liability and indemnity
13.1 Allocation Each party is responsible for its own compliance with Data Protection Law. Neither party will be liable to the extent a loss results from the other party’s unlawful instruction, breach or failure to meet its responsibilities.
13.2 Agreement limits Subject to liability that cannot lawfully be limited or excluded, each party’s liability arising under or in connection with this DPA is subject to the exclusions and aggregate caps in the Agreement. Claims under this DPA and the Agreement do not create separate or additional caps.
13.3 Statutory rights Nothing in this DPA limits a data subject’s rights or either party’s obligations to a supervisory authority under Data Protection Law.
14. Term and general terms
14.1 Term This DPA starts when Aspirium first processes Controller Personal Data and continues until that processing ends. Provisions that by their nature must continue, including confidentiality, deletion, audit, liability and international-transfer protections, survive termination for as long as relevant Controller Personal Data remains in processing.
14.2 Changes Aspirium may update this DPA where reasonably necessary to reflect changes in Data Protection Law, regulatory guidance, the Services or subprocessors. Material adverse changes will be notified in accordance with the Agreement. An update will not materially reduce protection for Controller Personal Data during a current paid term unless required by law or necessary to address a security risk.
14.3 Notices and general provisions The provisions on notices, assignment, subcontracting, severance, waiver, third-party rights and entire agreement in the Terms of Service apply to this DPA.
14.4 Governing law This DPA is governed by English law, and the courts of England and Wales have the jurisdiction stated in the Agreement.
Schedule 1 — Processing particulars
Item | Description |
Subject matter | Processing necessary to provide and support the Services ordered by the Customer, including hosting and related platform services, email, domains where relevant, migrations, website maintenance and fixes, support, backups and restoration, and optional digital, analytics, design or AI functions where enabled. |
Duration | For the term of the affected Service, plus limited periods required for export, secure deletion, legal retention and expiry or overwrite of protected backup and log copies. |
Nature of processing | Receiving, collecting, recording, organising, structuring, hosting, storing, retrieving, viewing, accessing, copying, transmitting, migrating, troubleshooting, securing, backing up, restoring, adapting where instructed, restricting and deleting data. |
Purpose | To provide, administer, maintain, secure, troubleshoot and support the contracted Services on the Customer’s documented instructions. |
Data subjects | Customer personnel and contractors; patients, prospective patients and service users; website visitors; enquiry and form submitters; newsletter or marketing recipients; suppliers and professional contacts; and other individuals whose data the Customer chooses to place in the Services. |
Personal data | Names and contact details; account identifiers and access data; website content, forms and enquiries; email and communications; booking or customer-service information where hosted; support and migration data; IP addresses, device, usage, security and log data; and content submitted to optional tools. |
Special-category data | Health or other special-category data only where the Customer chooses to process it, the Service is suitable, and the Order or service schedule permits it. Such data is not authorised for AI features unless expressly agreed in writing. |
Criminal-offence data | Not intended for routine processing and permitted only where expressly agreed in a written Order or service schedule with appropriate safeguards. |
Frequency | Continuous or intermittent, depending on the Customer’s use of the Services and support requests. |
Controller rights | All rights and obligations given to the Customer under this DPA, the Agreement and Data Protection Law. |
Schedule 2 — Technical and organisational measures
The following measures apply proportionately to the selected Service, the processing risks and the parts of the environment controlled by Aspirium or its authorised subprocessors:
- Access control: role-based or need-to-know access, least-privilege principles, account lifecycle controls and prompt removal of access when no longer required.
- Authentication: password and credential controls, secure handling of secrets, and multi-factor authentication for relevant administrative systems where supported and appropriate.
- Confidentiality: contractual confidentiality duties and access limited to personnel and suppliers requiring data for authorised purposes.
- Encryption: encryption of data in transit using appropriate protocols and encryption at rest where supported by the applicable platform, supplier and Service configuration.
- System security: security configuration, patching and vulnerability management appropriate to Aspirium-controlled systems, plus malware, abuse and threat controls where supported.
- Availability and resilience: redundant or resilient infrastructure and operational continuity measures appropriate to the Service; backups and restoration capabilities where included in the plan.
- Backups: protected backup copies, access controls and retention cycles appropriate to the applicable platform. Backups are subject to the limits and Customer responsibilities in the Agreement.
- Logging and monitoring: proportionate logging, platform monitoring and alerting for operational, security, fraud-prevention and support purposes, with access and retention controls.
- Incident management: processes to identify, escalate, contain, investigate, remediate and communicate security incidents and personal data breaches.
- Change and supplier management: reasonable diligence before engaging relevant suppliers, written data protection terms, controlled operational changes and periodic review of material suppliers.
- Data lifecycle: retention controls and secure deletion or overwrite processes appropriate to active data, support records, logs, decommissioned systems and backup cycles.
- Personnel awareness: relevant security and data protection guidance for persons with access to Controller Personal Data.
- Review: periodic evaluation of measures and reasonable improvements in response to material changes, incidents, identified risks and technical development.
Customer-controlled measures. The Customer remains responsible for endpoint security, user permissions, credentials, content and application configuration, software it controls, lawful retention settings, independent backups where appropriate, and secure use of exported or downloaded data.
Schedule 3 — Authorised subprocessors
The Customer authorises the following subprocessors and categories as at the effective date, but only to the extent they process Controller Personal Data for the Customer’s selected Services:
Subprocessor or category | Purpose | Processing location / safeguard |
hosting.com UK Services Ltd, providing the Stablepoint platform | Hosting platform, server and account administration, storage, network, security, backup and infrastructure-level support. | United Kingdom and the Customer’s selected hosting region; remote support or supplier access may occur elsewhere subject to clause 10. |
Datacentre, cloud, network, control-panel, email, DNS, security and backup suppliers used through Stablepoint | Underlying infrastructure and platform components required to provide Hosting Services. | The selected or notified service region and other support locations, using a lawful transfer mechanism where required. |
Support, migration and website-maintenance suppliers engaged for the Customer’s Service | Technical support, troubleshooting, migration, recovery, maintenance and security work. | As identified in the Order, service description or subprocessor notice; clause 10 applies to restricted transfers. |
Optional AI, analytics, website-building, communications or design-tool provider enabled for the Customer | Operation of an optional feature requested or enabled by the Customer. | As identified in the Order, in-product notice, service-specific schedule or subprocessor notice; clause 10 applies to restricted transfers. |
Current details and changes. Aspirium may make a current, more detailed list available in the client area, relevant service documentation or on request. A supplier that processes only Aspirium’s own controller data, such as ordinary account, payment or business-contact information, is governed by Aspirium’s Privacy Policy rather than this Schedule. Additions and replacements are governed by clause 9.







