Customer data processing agreement
UK GDPR processing terms for CoreCare customers.
This DPA applies when a customer order incorporates it and CoreCare processes personal data on that customer’s behalf.
Version 1.0 · 5 August 2026
Parties. The customer identified in the applicable order is the “Controller”. CoreCare Systems, trading from Red Lion, Fen Road, East Kirkby, Spilsby, PE23 4DB, United Kingdom, ICO registration reference C1999522, is the “Processor”. The order, customer terms and this DPA form the agreement.
1. Scope and priority
This DPA applies only to processing of personal data by CoreCare on the Controller’s behalf in providing the ordered CoreCare products, support, hosting, onboarding, export and deletion services. If this DPA conflicts with the customer terms on data protection, this DPA takes priority.
2. Definitions
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and binding legislation that replaces or supplements them. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given by Data Protection Law. “Subprocessor” means another processor engaged by CoreCare.
3. Documented instructions
CoreCare will process Customer Personal Data only on the Controller’s documented instructions, including the agreement, configured product use, authorised support requests and written instructions accepted by CoreCare. CoreCare will tell the Controller if an instruction appears to infringe Data Protection Law, unless law prohibits that notice. CoreCare will process data beyond those instructions only where required by applicable law and, unless prohibited, will tell the Controller before doing so.
4. Confidentiality and access
CoreCare will ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, receive access only where needed for their role and are informed of relevant data protection responsibilities. Customer administrators remain responsible for user permissions, lawful use and removing access that is no longer needed.
5. Security
CoreCare will implement appropriate technical and organisational measures having regard to the state of the art, implementation cost, the nature, scope, context and purposes of processing, and risks to people. Current baseline measures include encrypted network transport, provider-managed encryption at rest for hosted databases and object storage, server-side access and tenant checks, salted one-way password hashing, secure session cookies, rate limiting, security headers, operational monitoring, audit records, restricted support access, backup and recovery facilities, and incident handling. Product-specific measures and any agreed enhanced controls are recorded in the order or security schedule.
6. Subprocessors
The Controller gives general written authorisation for the subprocessors listed on the CoreCare subprocessor page. CoreCare will impose materially equivalent data protection obligations on each Subprocessor, remain responsible for its processor obligations, and provide notice of an intended addition or replacement so the Controller can raise a reasonable data-protection objection. If the parties cannot resolve an objection, either may end the affected service on written notice.
7. International transfers
CoreCare will not make a restricted transfer of Customer Personal Data without a lawful transfer mechanism and any supplementary measures required by Data Protection Law. On request, CoreCare will identify the relevant mechanism for an authorised Subprocessor. The Controller is responsible for its own transfers into and out of the service.
8. Data subject rights
Taking account of the nature of the processing, CoreCare will provide reasonable technical and organisational assistance for the Controller to respond to requests concerning access, correction, erasure, restriction, portability, objection or automated decision-making. If CoreCare receives a request that concerns Customer Personal Data, it will direct the requester to the Controller where appropriate and notify the Controller, unless prohibited by law. CoreCare will not respond on the Controller’s behalf without authorisation.
9. Breaches and compliance assistance
CoreCare will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will provide available information about the nature and likely consequences, affected data and people, containment or mitigation, and a contact point; information may be supplied in phases. CoreCare will reasonably assist with security, breach assessment and notification, data protection impact assessments and prior consultation, taking account of the processing and information available to CoreCare.
10. Records, audits and evidence
CoreCare will maintain records required of a Processor and make information reasonably necessary to demonstrate compliance with this DPA available to the Controller. No more than once each year, unless a breach or regulator reasonably requires more, the Controller may request relevant documentary evidence and an audit by an independent qualified auditor. Audits must protect other customers, confidential information and system security, occur on reasonable notice during business hours, and avoid unnecessary disruption. The Controller bears its audit costs unless the audit identifies a material CoreCare breach.
11. Return and deletion
During the service, the Controller may use available export functions or request a reasonable export. At the end of the affected service, CoreCare will, at the Controller’s choice, return or delete Customer Personal Data after the agreed retrieval period, and delete copies, unless applicable law requires retention. Deletion from active systems and expiry of protected recovery copies may occur on different schedules. Legal holds suspend deletion only for the affected records and are documented.
12. Controller responsibilities
The Controller confirms that its instructions and use have a lawful basis, that required notices are given, that special-category or criminal-offence data is used only where lawful and agreed, and that its users collect and disclose only necessary information. The Controller will configure retention and permissions, handle requests for its records, notify CoreCare promptly of relevant concerns, and not use demonstration environments for live sensitive information unless expressly approved.
Schedule 1 — processing details
| Subject and duration | Provision of the ordered CoreCare products for the agreement term, plus the documented return, deletion and recovery-copy expiry periods. |
|---|---|
| Nature and purpose | Hosting, organising, displaying, securing, supporting, backing up, exporting and deleting product records as instructed by the Controller. |
| Data subjects | Customer personnel, users, customers, suppliers and other people whose records the Controller lawfully enters. For CoreCare Care this may include clients, relatives, carers and other care professionals. |
| Personal data | Identity, contact, account, role, operational, booking, transaction, service, communications, device and audit information relevant to the ordered product. |
| Sensitive data | Only where the ordered product and written customer instructions require it. CoreCare Care may process health, care, medication and safeguarding information. Other products are not intended for special-category data unless expressly agreed. |
| Frequency | Continuous while authorised users use the service, with support, backup, export and deletion processing as needed. |
Schedule 2 — contact and variations
Operational privacy notices and requests may be sent to privacy@corecaresystems.co.uk. A change to this DPA that materially reduces protection will not apply during a current paid term without the Controller’s agreement, except where required by law.