Skip to content
Wakten
How it works Features See it live Who it's for
🇬🇧EN
🇬🇧 English 🇮🇹 Italiano 🇫🇷 Français
Request a demo
Overview Terms of Service Privacy Policy Data Processing Agreement Sub-processors Cookie Policy

Legal

Data Processing Agreement

Last updated: 7 October 2026

1. About this Agreement

This Data Processing Agreement ("DPA") forms part of the Wakten Terms of Service (the "Terms") between WAKTEN LTD, a company registered in England and Wales under company number 17501914, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Wakten", "Processor"), and the Customer that has accepted the Terms ("Customer", "Controller").

It sets out the terms on which Wakten processes personal data on the Customer's behalf when providing the Service, as required by Article 28 of the UK GDPR and the EU GDPR. It applies automatically when the Customer accepts the Terms, including during any free pilot or trial, and continues for as long as Wakten processes Customer Personal Data.

If this DPA conflicts with the Terms or a Customer Agreement on a data protection matter, this DPA prevails.

2. Definitions

Terms defined in the Terms have the same meaning here. In addition:

Term Meaning
Data Protection Law All laws on the processing of personal data that apply to a party, including the UK GDPR, the UK Data Protection Act 2018 and the EU GDPR (Regulation (EU) 2016/679), as amended or replaced.
Customer Personal Data Personal data within the Customer Data that Wakten processes on the Customer's behalf in providing the Service, as described in Annex 1.
Sub-processor Any third party Wakten engages to process Customer Personal Data.
Personal Data Breach A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
SCCs The standard contractual clauses for international transfers approved by the European Commission in Decision (EU) 2021/914.
UK Addendum The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, or the UK International Data Transfer Agreement.

"Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in Data Protection Law.

3. Roles of the parties

The Customer is the controller of Customer Personal Data and Wakten is its processor. Annex 1 describes the processing.

This DPA does not cover personal data that Wakten processes as a controller for its own purposes, such as account data about the Customer's Users and information about Wakten's business relationship with the Customer. That processing is described in Wakten's Privacy Policy.

4. Customer's obligations

The Customer is responsible for:

  • complying with Data Protection Law in its use of the Service, including having a lawful basis for processing Customer Personal Data and, for health information, a valid condition under Article 9 of the GDPR;

  • giving data subjects, including Patients who use its Booking Page, the information required by Data Protection Law;

  • making any registrations or declarations required by its supervisory authority, naming Wakten as its processor where required;

  • entering into the Service only the personal data it needs, and the accuracy of that data; and

  • ensuring that its instructions to Wakten comply with Data Protection Law.

5. Wakten's obligations

5.1 Instructions

Wakten will process Customer Personal Data only on the Customer's documented instructions, unless required to do otherwise by UK or EU law, in which case Wakten will inform the Customer before processing unless that law prohibits it. The Customer's instructions are set out in the Terms, this DPA and the Customer's use and configuration of the Service. Further instructions must be in writing and consistent with the Service.

Wakten will tell the Customer promptly if, in its opinion, an instruction infringes Data Protection Law.

Wakten will not use Customer Personal Data for its own purposes, and will never use Patient data for its own marketing or advertising, or sell it.

5.2 Confidentiality

Wakten will ensure that everyone it authorises to process Customer Personal Data is bound by an appropriate obligation of confidentiality and has access only to the extent needed to provide, support and secure the Service.

5.3 Security

Wakten will implement appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the GDPR. The current measures are described in Annex 3. Wakten may update them over time, provided the overall level of protection is not reduced.

5.4 Records

Wakten will keep a record of its processing activities carried out on behalf of the Customer, as required by Article 30(2) of the GDPR.

6. Sub-processors

6.1 General authorisation. The Customer gives Wakten general authorisation to engage Sub-processors. The Sub-processors in use at the date of this DPA are listed in Annex 2, and the Customer approves them.

6.2 Sub-processor obligations. Wakten will impose data protection obligations on each Sub-processor, by written contract, that offer at least the same level of protection as this DPA. Wakten remains responsible to the Customer for each Sub-processor's performance of those obligations.

6.3 Changes. Wakten will notify the Customer by email at least 30 days before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith. If it cannot be resolved, the Customer may end the Terms by written notice before the change takes effect, as its sole remedy, and will receive a pro rata refund of any fees it has prepaid for the period after termination.

6.4 Urgent replacement. Where a Sub-processor must be replaced urgently, for example for security reasons or because it stops providing its service, Wakten may make the change immediately and will notify the Customer as soon as possible afterwards. The objection right in clause 6.3 then applies.

7. International transfers

Wakten hosts the Service and stores Customer Personal Data in the European Union (see Annex 2). Wakten is established in the United Kingdom, which the European Commission recognises as providing an adequate level of protection.

Customer Personal Data may be transferred to, or accessed from, countries outside the UK and the European Economic Area only:

  • by the Sub-processors listed in Annex 2, as described there; and

  • by Wakten's authorised personnel, who may access the Service remotely from outside the UK and EEA, including from Morocco, to provide support and maintain the Service. The data remains stored in the EU and is accessed only over encrypted connections, by named personnel bound by confidentiality.

Where a transfer is made to a country without an adequacy decision (EU) or adequacy regulations (UK), Wakten will ensure it is protected by an appropriate safeguard under Article 46 of the GDPR, such as the SCCs (Module 3, processor to processor, for transfers to Sub-processors) together with the UK Addendum for UK data, or a recognised certification framework such as the EU-US Data Privacy Framework and its UK Extension. Wakten will provide a copy of the relevant safeguards on request.

8. Assistance to the Customer

8.1 Data subject requests. Taking into account the nature of the processing, Wakten will assist the Customer with appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their rights. If Wakten receives a request directly from a data subject about Customer Personal Data, it will forward it to the Customer without undue delay and will not respond itself, other than to direct the data subject to the Customer, unless the Customer instructs it to.

8.2 Other assistance. Taking into account the nature of the processing and the information available to it, Wakten will provide reasonable assistance to the Customer with its obligations on security, Personal Data Breach notification, data protection impact assessments and prior consultation with supervisory authorities.

Wakten may charge a reasonable fee for assistance that goes beyond what the Service normally provides, where the request is excessive or results from the Customer's own instructions. Wakten will tell the Customer before any charge applies.

9. Personal Data Breaches

Wakten will notify the Customer without undue delay after becoming aware of a Personal Data Breach. The notice will be sent to the Customer's account administrator and will include, as far as it is then available:

  • a description of the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;

  • the name and contact details of a person at Wakten who can provide more information;

  • the likely consequences of the breach; and

  • the measures taken or proposed to address the breach and reduce its possible adverse effects.

Where it is not possible to provide all of this information at once, Wakten will provide it in stages without further undue delay. Wakten will take reasonable steps to contain and investigate the breach and will cooperate with the Customer. The Customer is responsible for deciding whether to notify its supervisory authority and data subjects. Wakten's notification is not an acknowledgement of fault or liability.

10. Return and deletion

For 30 days after the Terms end, the Customer may ask Wakten to provide an export of its Customer Personal Data in a commonly used, machine-readable format. Wakten will then delete Customer Personal Data from its live systems within 90 days after the Terms end, unless UK or EU law requires it to keep the data. Copies in backups will be deleted as the backups are overwritten in the normal cycle. Wakten will confirm deletion in writing on request.

11. Audits and information

Wakten will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, for example by answering a reasonable security or data protection questionnaire.

If the information provided does not reasonably demonstrate compliance, or a supervisory authority requires it, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, subject to the following:

  • the Customer gives at least 30 days' written notice and agrees the scope, timing and duration with Wakten in advance;

  • audits take place no more than once in any 12-month period, unless required by a supervisory authority or following a Personal Data Breach;

  • audits are conducted during normal business hours, in a way that minimises disruption and does not give access to other customers' data or compromise Wakten's security; and

  • each party bears its own costs, except that the Customer pays any auditor it appoints.

12. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities under Data Protection Law where it cannot be limited.

13. Duration, changes and general

  • This DPA continues for as long as Wakten processes Customer Personal Data, including after the Terms end, until deletion under clause 10 is complete.

  • Wakten may update this DPA where required by changes in Data Protection Law, guidance from a supervisory authority or changes to the Service, by giving the Customer at least 30 days' notice. Changes will not reduce the protection given to Customer Personal Data.

  • If any part of this DPA is found unenforceable, the rest remains in force.

  • This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except where the SCCs or Data Protection Law require otherwise.

  • Questions about this DPA can be sent to contact@wakten.com.

Annex 1: Description of the processing

Item Details
Subject matter Provision of the Wakten online booking and patient-management Service to the Customer.
Duration For as long as the Terms are in force, and afterwards until deletion under clause 10.
Nature of processing Collection through the Booking Page and the Customer's Users, storage, organisation, retrieval, display, updating, sending of appointment emails, export and deletion.
Purpose To enable the Customer to manage its patients, practitioners' schedules and appointments, and to let patients book appointments online.
Data subjects The Customer's patients and clients, including people who book through the Booking Page, and people booking on their behalf (such as parents or guardians).
Categories of personal data First and last name; phone number; email address; preferred language; date of birth and postal address, where the Customer records them; appointment details (date, time, practitioner, service, price, status and how the booking was made); notes added by the Customer's staff; and, where the Customer uses the feature, clinical notes written by practitioners. Records of who accessed or changed patient data are also kept.
Special categories Information that appointments with health professionals, staff notes and clinical notes may reveal about a person's health (Article 9 GDPR). Additional safeguards are described in Annex 3.
Frequency Continuous, for as long as the Customer uses the Service.
Retention As determined by the Customer while the Terms are in force; deletion after termination under clause 10.

Annex 2: Approved Sub-processors

Sub-processor Purpose Location of processing Transfer safeguard
Hostinger International Ltd Hosting of the Service, database and backups Frankfurt, Germany (EU) Not applicable: processing within the EU
Resend, Inc. Delivery of appointment and service emails (recipient name, email address and email content) United States EU-US Data Privacy Framework and UK Extension; SCCs and UK Addendum incorporated in Resend's data processing agreement

Annex 3: Technical and organisational security measures

Access control

  • Each User has an individual account; shared accounts are not permitted.

  • Role-based permissions set by the Customer, so Users see only what their role allows.

  • Clinical notes are visible only to the practitioner who wrote them, and every access to them is logged.

  • Protection against password guessing through rate limiting and temporary account lockout.

  • Passwords are stored only as secure one-way hashes. Optional sign-in with Google.

  • Short-lived sign-in tokens held in memory rather than browser storage, renewed through a secure, HTTP-only cookie.

  • Access permissions and account status are checked on every request, so revoked access takes effect immediately.

Separation of data

  • Each Customer's data is logically separated from other Customers' data, and every request is restricted to the data of the clinic the User is signed in to.

Encryption

  • All data in transit is encrypted using HTTPS/TLS, including the connection between the application and the database.

Logging and monitoring

  • Audit logs of sensitive actions, including changes to appointments, roles and permissions, staff access changes and access to clinical notes.

  • Server and security logs kept for a limited period to detect and investigate incidents.

Availability and resilience

  • Hosting in a professional data centre in the EU, with regular automated backups.

  • Database-level protection against double bookings.

Organisational measures

  • Access to production systems is limited to named, authorised Wakten personnel bound by confidentiality, using individual credentials.

  • Changes to the Service are reviewed and tested before release.

  • Sub-processors are selected for their security standards and bound by written data protection terms.

  • Personal Data Breaches and data subject requests are handled as set out in clauses 8 and 9.

Wakten © 2026 WAKTEN LTD
Legal Privacy Policy Terms of Service Cookie Policy Contact