Legal
Data processing agreement
Outline. The signed version is issued per provider.
Parties and roles
The care provider is the controller. Hibba Ltd is the processor. Processing is limited to the provider's documented instructions, which are the functional specification and the provider's configuration.
Subject matter and duration
Care records, staff records and family portal accounts needed to deliver and evidence care, for the term of the service agreement plus the retention period the provider sets.
Processor obligations
- Confidentiality commitments for everyone with access.
- Technical and organisational measures as described on the security page.
- Sub-processors only from the published list, with 30 days notice of change and a right to object.
- Assistance with subject access, erasure and DPIAs.
- Personal data breach notification without undue delay and within 48 hours of confirmation.
- Return or deletion of data at the end of the service, in open formats, with certification.
- Audit and inspection rights for the controller, on reasonable notice.
International transfers
None outside the United Kingdom and the European Economic Area.
PlaceholderFull DPA text reviewed by a solicitor, with the UK Addendum and the liability clause, issued as PDF.