eselram
PrivacyTermsDPASubprocessors

Eselram · Data protection

Data Processing Agreement

The UK data-protection processing terms that apply when Eselram processes personal data on a customer’s behalf.

Effective: 19 September 2026

Part of the customer agreement: this DPA applies between the Eselram customer (Controller) and Marlese Rosch Haden trading as Eselram (Processor) whenever Eselram processes personal data on the customer's behalf.

1. Definitions and scope

Controller Personal Data means personal data processed by Eselram on behalf of the Controller in connection with Eselram. Data Protection Law means the UK GDPR, Data Protection Act 2018 and other applicable UK data-protection legislation as amended from time to time. Terms such as controller, processor, personal data, processing, personal data breach and data subject have the meanings given by Data Protection Law.

2. Processing details

Subject matter: provision, configuration, support, security, recovery and maintenance of Eselram.

Duration: the subscription and any agreed closure or recovery period, plus limited retention required by law.

Nature and purpose: provisioning, storage, transmission, email delivery, troubleshooting, backup or recovery, security and operational processing as applicable to the features configured or requested by the Controller.

Data subjects: may include the Controller's clients, prospective clients, staff, contractors and authorised users.

Personal data: may include identity and contact details, bookings, communications, payment references, forms, signatures, photographs, treatment or clinical records and other data entered or generated through the Controller's use of Eselram.

Special categories: may include health information where the Controller enables treatment or clinical workflows.

3. Controller instructions

Eselram will process Controller Personal Data only on documented instructions from the Controller, including these terms, the Terms of Service, configured service settings and written support instructions, unless UK law requires otherwise. If Data Protection Law permits, Eselram will inform the Controller before processing required by law. Eselram will promptly inform the Controller if, in Eselram's opinion, an instruction infringes Data Protection Law.

4. Confidentiality

Eselram will ensure that persons authorised to process Controller Personal Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality and access the data only as necessary for their role.

5. Security

Taking account of the state of the art, implementation costs, nature, scope, context and purposes of processing and the risks to individuals, Eselram will implement appropriate technical and organisational measures as required by Article 32 UK GDPR. Measures may include access controls, encrypted communications, environment separation, authentication controls, logging, backup/recovery controls and processes for maintaining service security, as appropriate to the architecture. The Controller remains responsible for security of its own infrastructure, users, devices, credentials and independently controlled integrations.

6. Subprocessors

The Controller gives Eselram general written authorisation to appoint subprocessors needed to provide the service. Eselram will maintain a current Subprocessors & Integrations Notice, ensure each subprocessor is bound by written data-protection obligations providing an appropriate level of protection for the processing it performs, and remain responsible to the Controller for performance of Eselram's processor obligations by its subprocessors.

Where required by Data Protection Law, Eselram will give reasonable advance notice of a material new subprocessor so the Controller may raise a reasonable, documented objection on data-protection grounds. The parties will work in good faith to address the concern. If no reasonable alternative is available, either party may discontinue the affected feature or terminate the affected service in accordance with the Terms.

7. Data-subject rights

Taking account of the nature of processing, Eselram will provide reasonable assistance by appropriate technical and organisational measures, insofar as possible, to enable the Controller to respond to requests to exercise data-subject rights. If Eselram receives a request relating to Controller Personal Data, it will not respond on the merits except on the Controller's instructions or where legally required, and may direct the requester to the Controller.

8. Personal data breaches

Eselram will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Personal Data. As information becomes reasonably available, Eselram will provide details needed to assist the Controller with its obligations, which may include the nature of the breach, categories of affected data and people, likely consequences, and measures taken or proposed. Eselram's notification does not constitute an admission of fault or liability.

9. Assistance and DPIAs

Taking account of the nature of processing and information available to Eselram, Eselram will provide reasonable assistance with the Controller's obligations concerning security, breach notification, data protection impact assessments and prior consultation with the ICO where Data Protection Law requires it.

10. International transfers

Eselram will not initiate a restricted transfer of Controller Personal Data except on documented instructions or where an applicable UK adequacy regulation, International Data Transfer Agreement, UK Addendum to approved standard contractual clauses or another lawful transfer mechanism applies. The Controller authorises transfers made by approved subprocessors in accordance with those safeguards. Customer-selected third-party accounts may create separate transfer responsibilities for the Controller.

11. Return and deletion

At the end of the paid service period, the Controller has a 30-day export/recovery window where applicable. At the Controller's choice, Eselram will delete or return Controller Personal Data processed by Eselram and delete remaining copies unless UK law requires storage. Where immediate deletion from backups is not technically practicable, the data will be put beyond ordinary use and removed through the normal secure deletion cycle. This clause does not require Eselram to delete data held solely in infrastructure independently controlled by the Controller, but Eselram will reasonably identify relevant closure steps.

12. Audit and compliance information

Eselram will make available information reasonably necessary to demonstrate compliance with applicable Article 28 processor obligations and allow and contribute to reasonable audits or inspections by the Controller or an auditor mandated by it. Audits must be proportionate, protect the confidentiality and security of other customers and Eselram systems, and ordinarily use existing documentation or remote evidence before intrusive inspection. Except following a qualifying breach or where a regulator requires otherwise, the Controller will give reasonable notice and bear its own audit costs.

13. Controller obligations

The Controller is responsible for ensuring that its instructions and processing are lawful, fair and transparent; identifying lawful bases and any required special-category conditions; providing privacy information; obtaining any required consent; data minimisation and accuracy; retention; user permissions; data-subject requests; and assessing whether its use of Eselram requires a DPIA or other safeguards.

14. Liability and order of terms

Liability arising under this DPA is subject to the liability provisions in the Terms of Service except to the extent Data Protection Law prohibits a limitation. If this DPA conflicts with the Terms on the processing of Controller Personal Data, this DPA takes priority to the extent of the conflict.

15. Contact

Processor: Marlese Rosch Haden trading as Eselram
Email: [email protected]

© 2026 Eselram. All rights reserved.
HomePrivacyTermsDPASubprocessorsSupport