Skip to content

Data Processing Agreement

Version 1.0 · 2 July 2026. This Agreement forms part of the subscription agreement between AesthetiClinic and the Customer (the clinic) and governs the processing of personal data under UK GDPR. Draft pending final legal review.

1. Roles and scope

For the personal data processed through the AesthetiClinic application, the Customer (the clinic) is the controller and AesthetiClinic is the processor. AesthetiClinic processes personal data only on the Customer's documented instructions, which include using the application in the ordinary way and the terms of this Agreement, unless required to do otherwise by law (in which case AesthetiClinic will inform the Customer first, unless the law prohibits it).

2. Subject-matter, duration, nature and purpose

The subject-matter is the provision of clinic-management software. The duration is the term of the subscription plus any period required for return or deletion. The nature and purpose is the hosting, storage, organisation and transmission of clinic and patient data so the Customer can run bookings, clinical records, consent, payments, messaging and reporting.

3. Types of personal data and categories of data subject

Data subjects: the Customer's patients, prospective patients and staff. Personal data includes contact and demographic details, appointment and payment records, marketing preferences, and staff account data. It includes special-category data: health and medical information (treatment records, medical histories, prescriptions, complications) and clinical photographs. The Customer is responsible for establishing a lawful basis and, for special-category data, an Article 9 condition for its own processing.

4. AesthetiClinic's obligations as processor

  • Instructions. Process personal data only on the Customer's documented instructions.
  • Confidentiality. Ensure personnel authorised to process the data are under a duty of confidentiality.
  • Security (Article 32). Implement appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control enforced at the database, tenant isolation between clinics, audit logging, and regular backups.
  • Sub-processors. Engage sub-processors only under the terms in section 6.
  • Data-subject rights. Assist the Customer, by appropriate technical and organisational measures, to respond to requests to exercise data-subject rights (access, rectification, erasure, portability, objection), including the one-click export and deletion features in the application.
  • Assistance. Assist the Customer with data-protection impact assessments, prior consultation, and security obligations, taking into account the information available to AesthetiClinic.
  • Breach notification. Notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal-data breach affecting the Customer's data, with the information the Customer needs to meet its own reporting duties.
  • Return or deletion. At the Customer's choice, return or delete all personal data at the end of the provision of services, and delete existing copies unless retention is required by law.
  • Audit. Make available the information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, by the Customer or an auditor it mandates, on reasonable notice.

5. International transfers

Personal data is hosted within the EU. Where a sub-processor processes data outside the UK or EEA (see the Annex), such transfers are made under an appropriate safeguard, in particular the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an adequacy decision where one applies.

6. Sub-processors

The Customer gives general authorisation for AesthetiClinic to engage the sub-processors listed in the Annex. AesthetiClinic imposes data-protection obligations on each sub-processor that are no less protective than those in this Agreement and remains liable to the Customer for their performance. AesthetiClinic will give the Customer reasonable prior notice of the addition or replacement of a sub-processor, and the Customer may object on reasonable data-protection grounds.

7. Liability and law

This Agreement is governed by the law of England and Wales. Liability under this Agreement is subject to the limitations set out in the subscription agreement. Nothing in this Agreement limits liability that cannot be limited by law.

Annex: Sub-processors

The current sub-processors engaged in providing the application. This list is kept up to date; the Customer is notified before a new sub-processor is added.

Sub-processor Purpose Location
Hetzner Online GmbH Cloud hosting and infrastructure for the application and its database Germany / EU
Supabase (self-hosted) Database, authentication and file storage, running on our EU Hetzner infrastructure Germany / EU
Stripe Payments Europe Payment processing for deposits and balances (on the clinic's own connected account) Ireland / EU, with onward transfers under SCCs
Resend Transactional and patient email delivery United States, under Standard Contractual Clauses
Amazon Web Services (SES) Transactional email delivery Ireland (eu-west-1) / EU
Twilio SMS reminders and messaging (when the clinic enables SMS) United States, under Standard Contractual Clauses
Anthropic Optional AI assistance for the platform support desk (drafting replies); customer data is not used for model training United States, under Standard Contractual Clauses

Questions about this Agreement or a signed counterpart: hello@aestheticlinic.io.