Data Processing Agreement
Last updated: 8 July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Wellspring Scheduling Ltd (“Processor”, “we”) and the practice that uses Wellspring (“Controller”, “you”). It sets out how we process personal data on your behalf under Article 28 of the UK/EU GDPR.
1. Roles
For client/patient data you enter into Wellspring, you are the controller and we are the processor. You are responsible for having a lawful basis (and, for health data, a valid Article 9 condition) and for providing privacy information to your clients. If you are based outside the UK/EEA, the UK/EU GDPR concepts in this DPA (controller, processor, Article 28/32) are the framework we use for every customer; you remain separately responsible for complying with your own country’s data-protection and health-privacy law (for example, Australia’s Privacy Act 1988 and, for health providers, the My Health Records Act 2012).
2. Scope of processing
- Subject matter: providing the Wellspring service.
- Duration: for the term of your subscription and any wind-down period.
- Nature & purpose: hosting, storing and processing data so you can run your practice.
- Data subjects: your clients/patients, contacts and staff.
- Categories of data: contact details, appointments, invoices/payments, communications, consent/disclaimer form responses (including the signer's IP address, device/browser and a timestamp, captured as evidence of signing), and — where you choose to record it — health information (special category data).
3. Our obligations
- Instructions: we process personal data only on your documented instructions (including via the app) and as needed to provide the service, unless required by law.
- Confidentiality: personnel authorised to process data are bound by confidentiality.
- Security: we implement appropriate technical and organisational measures under Article 32 — encryption in transit, access controls, per-practice data isolation, secure authentication and audit logging.
- Assistance: taking into account the nature of processing, we assist you in responding to data-subject requests and with your obligations under Articles 32–36 (security, breach, DPIAs).
- Breach notification: we notify you without undue delay after becoming aware of a personal-data breach affecting your data, so you can meet your own notification obligations under applicable law (for example, the UK/EU GDPR or, if you are based in Australia, the Notifiable Data Breaches scheme).
- Deletion/return: on termination we delete or return your personal data (your choice, where feasible), except where retention is required by law. You can also export your data from the app.
- Audits: we make available information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality and notice.
4. Sub-processors
You authorise us to engage the sub-processors below to process data on your behalf. We remain responsible for their performance, and we will give reasonable notice of changes so you can object.
- Neon — Database hosting (EU region) (Data storage).
- Vercel — Application hosting (Serving the app).
- Stripe — Payments & subscriptions (Card payments).
- PayPal / Square — Payment processing (if enabled) (Card payments).
- Meta Platforms — Advertising pixel (only with cookie consent) (Conversion tracking).
- Resend (AWS, EU region) — Email delivery — confirmations, reminders, campaigns (Notifications).
- Twilio — SMS delivery — reminders and campaigns (Notifications).
- Xero — Accounting sync (if connected) (Invoices & payments).
- Airtable — Helpdesk ticket metadata (internal support triage) (Support).
5. International transfers
Where a sub-processor is outside the UK/EEA, we ensure an appropriate transfer mechanism is in place (such as an adequacy decision or Standard Contractual Clauses). If you are the Controller and are based outside the UK/EEA (for example, in Australia), sending personal data to us involves an overseas disclosure under your own law — you are responsible for meeting any notice or due-diligence obligations that creates (such as Australian Privacy Principle 8), and we will provide information you reasonably need to assess that.
6. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
7. General
If there is a conflict between this DPA and the Terms on data-protection matters, this DPA prevails. This DPA is governed by the laws of England & Wales. For data-protection queries, contact privacy@wellspring.example.
Questions about this page? Contact us at privacy@wellspring.example.
