1. Definitions and scope
Controller Personal Data means personal data processed by Eselram on behalf of the Controller in connection with Eselram. Data Protection Law means the UK GDPR, Data Protection Act 2018 and other applicable UK data-protection legislation as amended from time to time. Terms such as controller, processor, personal data, processing, personal data breach and data subject have the meanings given by Data Protection Law.
2. Processing details
Subject matter: provision, configuration, support, security, recovery and maintenance of Eselram.
Duration: the subscription and any agreed closure or recovery period, plus limited retention required by law.
Nature and purpose: provisioning, storage, transmission, email delivery, troubleshooting, backup or recovery, security and operational processing as applicable to the features configured or requested by the Controller.
Data subjects: may include the Controller's clients, prospective clients, staff, contractors and authorised users.
Personal data: may include identity and contact details, bookings, communications, payment references, forms, signatures, photographs, treatment or clinical records and other data entered or generated through the Controller's use of Eselram.
Special categories: may include health information where the Controller enables treatment or clinical workflows.
3. Controller instructions
Eselram will process Controller Personal Data only on documented instructions from the Controller, including these terms, the Terms of Service, configured service settings and written support instructions, unless UK law requires otherwise. If Data Protection Law permits, Eselram will inform the Controller before processing required by law. Eselram will promptly inform the Controller if, in Eselram's opinion, an instruction infringes Data Protection Law.
4. Confidentiality
Eselram will ensure that persons authorised to process Controller Personal Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality and access the data only as necessary for their role.
5. Security
Taking account of the state of the art, implementation costs, nature, scope, context and purposes of processing and the risks to individuals, Eselram will implement appropriate technical and organisational measures as required by Article 32 UK GDPR. Measures may include access controls, encrypted communications, environment separation, authentication controls, logging, backup/recovery controls and processes for maintaining service security, as appropriate to the architecture. The Controller remains responsible for security of its own infrastructure, users, devices, credentials and independently controlled integrations.
6. Subprocessors
The Controller gives Eselram general written authorisation to appoint subprocessors needed to provide the service. Eselram will maintain a current Subprocessors & Integrations Notice, ensure each subprocessor is bound by written data-protection obligations providing an appropriate level of protection for the processing it performs, and remain responsible to the Controller for performance of Eselram's processor obligations by its subprocessors.
Where required by Data Protection Law, Eselram will give reasonable advance notice of a material new subprocessor so the Controller may raise a reasonable, documented objection on data-protection grounds. The parties will work in good faith to address the concern. If no reasonable alternative is available, either party may discontinue the affected feature or terminate the affected service in accordance with the Terms.
7. Data-subject rights
Taking account of the nature of processing, Eselram will provide reasonable assistance by appropriate technical and organisational measures, insofar as possible, to enable the Controller to respond to requests to exercise data-subject rights. If Eselram receives a request relating to Controller Personal Data, it will not respond on the merits except on the Controller's instructions or where legally required, and may direct the requester to the Controller.
8. Personal data breaches
Eselram will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Personal Data. As information becomes reasonably available, Eselram will provide details needed to assist the Controller with its obligations, which may include the nature of the breach, categories of affected data and people, likely consequences, and measures taken or proposed. Eselram's notification does not constitute an admission of fault or liability.
9. Assistance and DPIAs
Taking account of the nature of processing and information available to Eselram, Eselram will provide reasonable assistance with the Controller's obligations concerning security, breach notification, data protection impact assessments and prior consultation with the ICO where Data Protection Law requires it.
10. International transfers
Eselram will not initiate a restricted transfer of Controller Personal Data except on documented instructions or where an applicable UK adequacy regulation, International Data Transfer Agreement, UK Addendum to approved standard contractual clauses or another lawful transfer mechanism applies. The Controller authorises transfers made by approved subprocessors in accordance with those safeguards. Customer-selected third-party accounts may create separate transfer responsibilities for the Controller.
11. Return and deletion
At the end of the paid service period, the Controller has a 30-day export/recovery window where applicable. At the Controller's choice, Eselram will delete or return Controller Personal Data processed by Eselram and delete remaining copies unless UK law requires storage. Where immediate deletion from backups is not technically practicable, the data will be put beyond ordinary use and removed through the normal secure deletion cycle. This clause does not require Eselram to delete data held solely in infrastructure independently controlled by the Controller, but Eselram will reasonably identify relevant closure steps.
12. Audit and compliance information
Eselram will make available information reasonably necessary to demonstrate compliance with applicable Article 28 processor obligations and allow and contribute to reasonable audits or inspections by the Controller or an auditor mandated by it. Audits must be proportionate, protect the confidentiality and security of other customers and Eselram systems, and ordinarily use existing documentation or remote evidence before intrusive inspection. Except following a qualifying breach or where a regulator requires otherwise, the Controller will give reasonable notice and bear its own audit costs.
13. Controller obligations
The Controller is responsible for ensuring that its instructions and processing are lawful, fair and transparent; identifying lawful bases and any required special-category conditions; providing privacy information; obtaining any required consent; data minimisation and accuracy; retention; user permissions; data-subject requests; and assessing whether its use of Eselram requires a DPIA or other safeguards.
14. Liability and order of terms
Liability arising under this DPA is subject to the liability provisions in the Terms of Service except to the extent Data Protection Law prohibits a limitation. If this DPA conflicts with the Terms on the processing of Controller Personal Data, this DPA takes priority to the extent of the conflict.
15. Contact
Processor: Marlese Rosch Haden trading as Eselram
Email: [email protected]