CareMaSym

Legal & trust

Data Processing Addendum

Article 28 processing terms for CareMaSym customers.

Effective 25 July 2026

Article 28 processing terms for CareMaSym customers.

1. Scope and roles

This DPA forms part of the Agreement between the CareMaSym provider in the Order Form (“Processor”) and customer (“Controller”). The Controller determines purposes and means. The Processor acts only on documented instructions unless UK law requires otherwise.

2. Processing details

Subject matter: care-management software and support.

Duration: the Agreement term plus authorised return, deletion and backup periods.

Purpose: hosting, organising, transmitting, securing, backing up, reporting and support.

Data subjects: service users, relatives, staff, professionals and authorised users.

Data: identity, contact, account, rota, location, communication, audit and care data, including health and safeguarding information.

3. Confidentiality and security

Authorised personnel are bound by confidentiality and receive appropriate training. Measures appropriate to risk include access control, authentication, encryption in transit, tenant scoping, logging, vulnerability management, backup controls, incident response and supplier review. Measures may evolve without materially reducing overall protection.

4. Sub-processors

The Controller gives general authorisation for providers in the Sub-processor Register. We give reasonable prior notice of material additions and permit reasonable data-protection objections. Equivalent Article 28 obligations apply by written contract, and the Processor remains responsible as required by law.

5. Rights and compliance assistance

Taking account of processing and available information, the Processor reasonably assists with data-subject requests, security, breach notification, impact assessments and regulator consultation. Direct requests are referred to the Controller unless law requires otherwise.

6. Personal-data breaches

The Processor notifies the Controller without undue delay after becoming aware of a Customer Personal Data breach and provides available information needed for assessment and notification. Notice is not an admission of fault.

7. International transfers

Restricted transfers occur only on documented instruction or through an authorised provider and use adequacy, the UK IDTA, UK Addendum or another lawful mechanism, with supplementary measures where appropriate.

8. Return and deletion

After services end, the Processor returns or deletes Customer Personal Data at the Controller’s choice and as set out in the Agreement, except where law requires retention. Protected backups remain isolated and expire through the normal lifecycle.

9. Information and audits

We provide information reasonably necessary to demonstrate Article 28 compliance. Reviews should first use reports and questionnaires. Additional inspection may occur on reasonable notice, subject to confidentiality, security and non-disruption safeguards.

10. Priority and contact

This DPA prevails for Customer Personal Data where it conflicts with the Agreement; an applicable transfer mechanism prevails for its transfer. Contact hello@caremasym.com and retain a dated copy with the Agreement.

This CMS-managed page may be updated after legal, product or supplier review. Questions: hello@caremasym.com.