Skip to main content
Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Babiha Care Solutions Limited ("Babiha", "we") and the care agency customer ("Customer", "you"). It sets out the terms required by Article 28 of the UK GDPR on which we process personal data on your behalf. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.

1. Roles of the Parties

For the service user and care-related personal data you enter into the platform, you are the controller and Babiha is the processor. You are responsible for ensuring you have a lawful basis and, for special category (health) data, an Article 9 condition, and for providing the necessary privacy information to service users and staff. Babiha is a separate controller only for the limited account and operational data described in its Privacy Policy.

2. Our Obligations as Processor

We agree that we shall:

  • (a) Documented instructions. Process the personal data only on your documented instructions (including regarding international transfers), unless required to do otherwise by law, in which case we will inform you first unless the law prohibits it. Your instructions are set out in the Terms, this DPA, and your use of the platform.
  • (b) Confidentiality. Ensure that everyone authorised to process the personal data is bound by an appropriate duty of confidentiality.
  • (c) Security. Implement the appropriate technical and organisational measures required by Article 32, as described in Schedule 2.
  • (d) Sub-processors. Only engage sub-processors under the terms in Section 3.
  • (e) Data subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, so far as possible, to respond to requests from individuals exercising their rights.
  • (f) Assistance with compliance. Assist you in ensuring compliance with your obligations on security (Article 32), personal data breaches (Articles 33–34), data protection impact assessments (Article 35) and prior consultation (Article 36), taking into account the nature of processing and the information available to us.
  • (g) Return or deletion. At the end of the services, at your choice, delete or return all the personal data and delete existing copies, unless the law requires us to keep it (see Section 5).
  • (h) Audits and information. Make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections as set out in Section 6.
  • (i) Infringing instructions. Immediately inform you if, in our opinion, an instruction infringes UK data protection law.

3. Sub-processors

You provide general written authorisation for us to engage the sub-processors listed on our Sub-processors page. We will inform you of any intended addition or replacement of a sub-processor (you may subscribe to notifications), giving you the opportunity to object on reasonable data protection grounds. We impose the same data protection obligations on each sub-processor by written contract and remain fully liable to you for their performance of those obligations.

4. International Transfers

Our primary hosting is in the United Kingdom. Where a sub-processor is located outside the UK, we ensure an appropriate transfer mechanism is in place — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or reliance on the UK Extension to the EU–US Data Privacy Framework where the provider is certified. We will not transfer personal data outside the UK other than as described on our Sub-processors page without your instruction or an appropriate safeguard.

5. Personal Data Breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, providing the information you need to meet your own notification obligations to the ICO (which must generally be met within 72 hours) and to affected individuals where required.

6. Return and Deletion

On termination or expiry of the services, we will, at your choice and on your written request, return or delete the personal data we process on your behalf, and delete existing copies, within a reasonable period, unless we are required by law to retain it.

7. Audits

We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint, on reasonable prior notice, no more than once per year (unless required more frequently by a regulator or following a breach), and subject to appropriate confidentiality obligations.

8. Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where the law does not permit those limitations to apply.


Schedule 1 — Details of the Processing

  • Subject matter: provision of the Babiha care management platform.
  • Duration: for the term of the Customer's subscription, plus any return/deletion period.
  • Nature and purpose: hosting, storage, and processing of care records to enable care planning, scheduling, medication administration, visit logging, reporting, and family communication.
  • Types of personal data: identity and contact data; special category health data; care plans, risk assessments and medication records; visit and care notes; staff account and scheduling data; family contact data.
  • Categories of data subjects: service users (clients), their next of kin and family members, and the Customer's staff.

Schedule 2 — Security Measures

We maintain technical and organisational measures including:

  • Encryption of data in transit (TLS). Data at rest is encrypted by our hosting provider under the terms they publish for their platform
  • Additional application-layer encryption (AES-256-GCM) of the most sensitive fields, such as NHS numbers, key safe codes and bank details
  • Role-based access control across distinct user roles, and database-level Row Level Security enforcing complete separation between agencies
  • Two-factor authentication, session management and password strength enforcement
  • Immutable audit logging with automatic redaction of personal data in logs
  • Rate limiting, strict input validation, and a nonce-based Content Security Policy
  • Regular internal security reviews, dependency and secret scanning, and code review

Full detail is on our Security page.

Schedule 3 — Sub-processors

The current list of authorised sub-processors is published and maintained on our Sub-processors page.


Questions about this DPA can be sent to our Data Protection Lead at dpo@babiha.care.