United Kingdom · UK GDPR
UK GDPR Data Processing Agreement
Version 2026-09-11Effective 11 September 2026
This document is incorporated by reference into 2care.ai service agreements. Where it conflicts with a signed Order Form, the Order Form controls the specific item it addresses.
This Data Processing Agreement (the DPA) forms part of the Service Agreement between 2Care AI Inc. and the clinic identified on the Order Form (the Clinic) and governs the processing of personal data through the Services. Because the Services handle patient personal data, including health information that is special-category data, both parties commit to the following.
1. Roles
The Clinic is the Data Controller and 2care is the Data Processor, processing personal data only on the Clinic's documented instructions, which include the Agreement. Both parties will comply with the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR.
2. Scope of processing
- Subject matter: providing the AI receptionist, outbound lead calling, booking and follow-up service.
- Duration: the term of the Agreement.
- Nature and purpose: calling and qualifying leads, answering inbound calls, and booking, rescheduling and managing appointments.
- Data subjects: the Clinic's patients, prospects and callers.
- Personal data: name, contact details, appointment details, call content, enquiry and interest data.
- Special category: health information disclosed by patients or leads in the course of booking or enquiry.
3. 2care's obligations as processor
- Process personal data only on the Clinic's documented instructions, unless required otherwise by law (in which case 2care will inform the Clinic first, where legally permitted).
- Ensure that persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures, including encryption in transit and at rest, access controls and secure handling end to end; patient and lead data is not stored or shared outside the secure processing pipeline.
- Not engage another sub-processor without the Clinic's prior general or specific written authorisation, and ensure any sub-processor (for example telephony, SMS, cloud-hosting or integration providers) is bound by equivalent obligations; a current list of sub-processors is available on request.
- Assist the Clinic in responding to data-subject requests (access, rectification, erasure, objection, portability).
- Assist the Clinic with security, breach notification, data protection impact assessments and consultation with the ICO where required.
- Notify the Clinic without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach.
- On termination, at the Clinic's choice, delete or return all personal data and delete existing copies, unless law requires storage.
- Make available information necessary to demonstrate compliance and allow for reasonable audits by the Clinic or its appointed auditor.
4. International transfers
2care is incorporated in the United States. Where personal data is transferred outside the UK, 2care will ensure an appropriate safeguard is in place, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, so the data receives a level of protection essentially equivalent to that under UK law.
5. The Clinic's obligations as controller
- Ensure it has a lawful basis for the processing and, for special-category (health) data, an appropriate Article 9 condition.
- Provide patients and leads with the necessary privacy information about the use of the Services, including that outbound calls may be made on the Clinic's behalf by an AI agent.
- Ensure that any lead lists shared with 2care have been collected in compliance with the UK GDPR and that individuals have been given appropriate notice of how their data may be used.
- Issue only lawful processing instructions.
6. Liability
Each party is responsible for its own compliance with data-protection law. The liability limits in the Agreement apply to this DPA, except where the law does not permit them. This document is a plain-language agreement and not legal advice; both parties should have it reviewed by a qualified solicitor before signing.