Data Processing Agreement
This template governs the processing of personal information about patients on behalf of GP practices using CommunityCare. It is incorporated by reference into our Terms of Service. The signed version takes precedence; this page is the canonical reference.
Last updated · 11 June 2026
Note: This document is the publicly published version. Where a GP practice partner ("Customer") has signed a bespoke Data Processing Agreement with us, that signed document supersedes this one. To request a signed copy email privacy@community-care.app.
1. Definitions
Terms used in this document have the meanings given in the Protection of Personal Information Act, 2013 ("POPIA") for South African Customers, in the UK General Data Protection Regulation and Data Protection Act 2018 for UK Customers, and in the Data Privacy Act of 2012 (Republic Act 10173) for Philippine Customers, as applicable. The Customer is the responsible party / data controller / personal information controller; CommunityCare is the operator / data processor /personal information processor.
2. Subject matter and duration
CommunityCare processes personal information on behalf of the Customer for the purpose of providing the care-coordination service described at community-care.app. Processing continues for the duration of the Customer's subscription and ends as described in Section 11.
3. Nature and purpose
The nature of processing is automated storage, organisation, retrieval, transfer and structured display of patient records to authorised users in the Customer's organisation and the patient's family circle. The purpose is to enable better coordination of routine care between visits.
4. Categories of data subjects
- Patients of the Customer's practice for whom records are created.
- Caregivers and family members invited into a patient's circle by the Customer.
- Clinicians and staff of the Customer's organisation.
5. Categories of personal information
- Identity and contact details
- Special personal information / special category data: health and medical history, medication, allergies, mental capacity, DNR preferences, biometric vital signs, photographic records of wounds and pressure areas
- Activity records (audit log)
6. CommunityCare's obligations as operator / processor
CommunityCare will:
- Process personal information only on the Customer's documented instructions, including with respect to transfers outside the territory in which the Customer is established, except as required by law;
- Ensure persons authorised to process the personal information are bound by an obligation of confidentiality;
- Implement appropriate technical and organisational measures, as set out in our Security page, to protect the personal information against accidental or unlawful loss, destruction or damage and against unauthorised access;
- Assist the Customer with responding to data subject rights requests (access, correction, erasure, restriction) through the in-platform tools and, where those are insufficient, through manual support within reasonable timeframes;
- Notify the Customer without undue delay (and in any event within 48 hours) on becoming aware of a personal data breach affecting their personal information, with sufficient information to allow the Customer to meet its own notification obligations under applicable law;
- Make available all information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer (no more than annually except in case of incident, on reasonable notice and during business hours, and subject to confidentiality);
- Inform the Customer immediately if, in our opinion, an instruction infringes applicable data protection law.
7. Sub-processing
The Customer authorises CommunityCare to engage the sub-processors listed at /legal/sub-processors. We may engage additional sub-processors subject to giving the Customer at least 30 days' prior notice and the right to object. Where the Customer objects on reasonable grounds we will, at our option, refrain from engaging the sub-processor or terminate the affected portion of the service.
8. Cross-border transfer
For South African Customers, transfer of personal information to the United Kingdom is permitted under POPIA s.72(1)(a) — the United Kingdom provides a level of protection substantially similar to POPIA via the UK GDPR and Data Protection Act 2018. This is supported by the standard contractual clauses with the UK Information Commissioner's Addendum incorporated into our written processing agreement with Supabase.
For Philippine Customers, the Customer specifically and informedly authorises the transfer of personal information to the United Kingdom under section 21 of the Data Privacy Act of 2012 and NPC Circular 16-02 on Cross-Border Data Transfers. CommunityCare, as the Personal Information Processor (PIP), commits to: (a) implementing the same security measures as the Customer applies in the Philippines; (b) being subject to the same contractual obligations regarding confidentiality and data subject rights; and (c) being bound by the standard contractual clauses agreed with Supabase, which incorporate equivalent protections to those of the Philippine DPA. The Customer remains the Personal Information Controller (PIC) and the appointed Data Protection Officer at CommunityCare assists with NPC interactions.
For UK Customers, no cross-border transfer is engaged because the data remains in the UK.
9. Security measures
Set out in detail at /security. Summary: TLS 1.2+ in transit, AES-256 at rest, role-based and org-isolated access control, immutable audit log, daily encrypted backups with 7-day PITR, multi-factor authentication for engineering access.
10. Data subject rights
The Customer remains responsible for responding to data subject requests. We provide the technical means (in-app export, in-app erasure request) and, where manual assistance is needed, provide it without additional charge.
11. Return or deletion at end of service
On termination of the Customer's subscription, CommunityCare will, at the Customer's option, return all personal information processed on their behalf or delete it, save for any copy required to be retained under applicable law. The Customer must elect within 30 days; in default we delete. Audit log entries relating to the Customer's processing are retained for the statutory period of 7 years as required for our own compliance.
12. Liability and indemnity
Liability between the parties is as set out in our Terms of Service. Each party indemnifies the other against fines and claims arising from its own non-compliance with applicable data protection law.
13. Order of precedence
Where this Data Processing Agreement conflicts with the main Terms of Service in respect of personal information processing, this Agreement prevails. Where a signed bespoke DPA exists, that signed document prevails over this template.
Contact
For all queries arising under this DPA: privacy@community-care.app.