1. Background and Roles
This Data Processing Agreement ("DPA") is entered into between CallidusOS Limited ("Processor") and the subscribing Clinic ("Controller") as part of the Master Terms and Conditions.
The Clinic acts as Data Controller in respect of Clinical Data belonging to its patients. CallidusOS acts as Data Processor, processing Clinical Data solely on the documented instructions of the Clinic.
CallidusOS also acts as an independent Data Controller in respect of business contact data, billing data, and usage analytics relating to the Clinic and its staff.
2. Scope of Processing
Purpose: To provide the CallidusOS® platform services, including Calia Copilot decision support, to the Clinic.
Nature: Storage, retrieval, analysis (via Calia Copilot), transmission, and deletion of Clinical Data.
Types of data: Patient names, contact details, medical history, treatment records, consent records, and other clinical information uploaded by the Clinic.
Categories of data subjects: Patients and prospective patients of the Clinic.
Duration: For the term of the Agreement and as set out in the Retention and Deletion Policy.
3. Processor Obligations
CallidusOS shall:
• Process Clinical Data only on documented instructions from the Clinic, unless required to do so by applicable law.
• Ensure that all personnel authorised to process Clinical Data are subject to appropriate confidentiality obligations.
• Implement and maintain appropriate technical and organisational security measures.
• Not engage any sub-processor without prior written notification to the Clinic.
• Assist the Clinic in responding to data subject rights requests within 72 hours of receipt.
• Notify the Clinic of any personal data breach affecting Clinical Data within 24 hours of becoming aware of it.
• On termination, delete or return all Clinical Data as directed by the Clinic within 30 days.
• Make available all information reasonably necessary to demonstrate compliance with this DPA and permit audits on reasonable notice.
4. Sub-Processors
CallidusOS shall give the Clinic not less than 14 days' written notice before adding or replacing any sub-processor. The Clinic may object to any such change within 14 days of notification; if the Parties cannot resolve the objection, either Party may terminate the Agreement on 30 days' notice.
5. International Transfers
Some sub-processors (Stripe, Twilio, SendGrid) may process data outside the UK or EU. CallidusOS ensures that all such transfers are governed by Standard Contractual Clauses (SCCs) or equivalent safeguards approved under UK GDPR.
6. Security and Breach Notification
CallidusOS shall implement and maintain security measures including AES-256 encryption at rest, TLS 1.3 in transit, and access controls.
In the event of a personal data breach affecting Clinical Data, CallidusOS shall notify the Clinic within 24 hours, providing sufficient detail to enable the Clinic to meet its own ICO reporting obligations (72-hour window from awareness).
7. Governing Law
This DPA is governed by the laws of England and Wales and shall be interpreted in accordance with UK GDPR and the Data Protection Act 2018.
CallidusOS Limited · Company No. 16902276 · ICO Registration ZC066513
Questions about this document? Email hello@callidusos.co.uk.