Data Processing Agreement
Last updated: 7 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Babiha Care Solutions Limited ("Babiha", "we") and the care agency customer ("Customer", "you"). It sets out the terms required by Article 28 of the UK GDPR on which we process personal data on your behalf. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.
1. Roles of the Parties
For the service user and care-related personal data you enter into the platform, you are the controller and Babiha is the processor. You are responsible for ensuring you have a lawful basis and, for special category (health) data, an Article 9 condition, and for providing the necessary privacy information to service users and staff. Babiha is a separate controller only for the limited account and operational data described in its Privacy Policy.
2. Our Obligations as Processor
We agree that we shall:
- (a) Documented instructions. Process the personal data only on your documented instructions (including regarding international transfers), unless required to do otherwise by law, in which case we will inform you first unless the law prohibits it. Your instructions are set out in the Terms, this DPA, and your use of the platform.
- (b) Confidentiality. Ensure that everyone authorised to process the personal data is bound by an appropriate duty of confidentiality.
- (c) Security. Implement the appropriate technical and organisational measures required by Article 32, as described in Schedule 2.
- (d) Sub-processors. Only engage sub-processors under the terms in Section 3.
- (e) Data subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, so far as possible, to respond to requests from individuals exercising their rights.
- (f) Assistance with compliance. Assist you in ensuring compliance with your obligations on security (Article 32), personal data breaches (Articles 33–34), data protection impact assessments (Article 35) and prior consultation (Article 36), taking into account the nature of processing and the information available to us.
- (g) Return or deletion. At the end of the services, at your choice, delete or return all the personal data and delete existing copies, unless the law requires us to keep it (see Section 6).
- (h) Audits and information. Make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections as set out in Section 7.
- (i) Infringing instructions. Immediately inform you if, in our opinion, an instruction infringes UK data protection law.
3. Sub-processors
You provide general written authorisation for us to engage the sub-processors listed on our Sub-processors page. We will inform you of any intended addition or replacement of a sub-processor directly through your agency contact before that provider processes your data, giving you the opportunity to object on reasonable data protection grounds. We will impose the same data protection obligations on each sub-processor by written contract before permitting it to process Customer Data and remain fully liable to you for their performance of those obligations.
4. International Transfers
Our primary database hosting is in the United Kingdom. Before a restricted transfer, we will establish a lawful transfer mechanism, such as applicable UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses, and complete any required transfer assessment. The UK Extension to the EU–US Data Privacy Framework applies only to eligible recipients and transfers. Transfers must also be authorised by your documented instructions. Our Sub-processors page records the status of provider arrangements; an unverified status is not confirmation that a required safeguard is already in place.
5. Personal Data Breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, providing the information you need to meet your own notification obligations to the ICO (which must generally be met within 72 hours of becoming aware where the breach is reportable) and to affected individuals where required. Initial information may be provided in stages as the investigation progresses; we will not wait for all details before notifying you.
6. Return and Deletion
On termination or expiry of the services, we will, at your choice, return or delete the personal data we process on your behalf, and delete existing copies, within a reasonable period, unless we are required by law to retain it. We will contact you to agree your instructions and explain any legally required retention; silence does not authorise indefinite use of Customer Data.
7. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint, on reasonable prior notice, normally once per year, with additional audits where reasonably needed to verify compliance, after a breach or when required by a regulator, and subject to appropriate confidentiality obligations.
8. Liability
The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where the law does not permit those limitations to apply. Nothing in this DPA limits an individual's statutory rights or either party's direct responsibilities under data protection law.
Schedule 1 — Details of the Processing
- Subject matter: provision of the Babiha care management platform.
- Duration: for the term of the Customer's subscription, plus any return/deletion period.
- Nature and purpose: hosting, storage, and processing of care records to enable care planning, scheduling, medication administration, visit logging, reporting, and family communication.
- Types of personal data: identity and contact data; special category health data; care plans, risk assessments and medication records; visit and care notes; staff account and scheduling data; family contact data.
- Categories of data subjects: service users (clients), their next of kin and family members, and the Customer's staff.
Schedule 2 — Security Measures
We maintain technical and organisational measures including:
- Encryption of data in transit (TLS). Data at rest is encrypted by our hosting provider under the terms they publish for their platform
- Additional application-layer encryption (AES-256-GCM) of the most sensitive fields, such as NHS numbers, key safe codes and bank details
- Role-based access control across distinct user roles, and database-level Row Level Security policies restricting access between agencies
- Two-factor authentication, session management and password strength enforcement
- Audit logging protected against routine alteration, with personal-data redaction controls
- Rate limiting, strict input validation, and a nonce-based Content Security Policy
- Regular internal security reviews, dependency and secret scanning, and code review
Full detail is on our Security page.
Schedule 3 — Sub-processors
The current list of authorised sub-processors is published and maintained on our Sub-processors page.
Questions about this DPA can be sent to our Data Protection Lead at dpo@babiha.care.