Data Processing Agreement
Version 1.1 · Last updated July 2026 · Last reviewed: July 2026
1. Parties
This Data Processing Agreement (“DPA”) is entered into between:
- Data Controller: The therapist or organisation (“you”, “Controller”) who creates an account on Formulate and enters client data.
- Data Processor: Formulate Tools Ltd, Company No. 17065550, registered in England & Wales, 11 Chantry Close, Sunbury-on-Thames, TW16 7TH (“we”, “Processor”).
This DPA supplements the Terms of Service and Privacy Policy.
2. Subject matter & duration
The Processor processes personal data on behalf of the Controller for the purpose of providing the Formulate platform — a clinical psychology worksheet and formulation tool. Processing begins when the Controller creates an account and continues until the account is deleted or this DPA is terminated.
3. Nature & purpose of processing
Processing includes:
- Storage and display of pseudonymised client records (labels, case notes, assigned worksheets)
- Storage and display of client-submitted homework responses
- AI-assisted worksheet generation using PII-stripped input
- Email delivery for homework links and account notifications
- Payment processing for subscription billing
4. Types of personal data
Therapist data
Email address, name, organisation name (optional), subscription and billing details, usage logs.
Client data (pseudonymised)
Client labels (initials or codes — never full names or email addresses), worksheet responses, homework completion status. The platform validates client labels to reject obvious identifiers (such as emails, phone numbers, NHS/NI numbers, dates of birth and postcodes) and warns against using names; the Controller remains responsible for not entering identifiable information.
Special category data
Worksheet responses may contain health-related data. All such data is pseudonymised and encrypted at rest (AES-256). Only the assigning therapist can access response content.
5. Data subjects
- Therapists and other healthcare professionals who use the platform
- Clients of those therapists (pseudonymised records only)
6. Processor obligations
6.1 Documented instructions
The Processor will process personal data only on the documented instructions of the Controller, including with regard to transfers of personal data to a third country, unless required to do otherwise by UK law — in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
The Controller's documented instructions are: this DPA, the Terms of Service, and the Controller's use of the platform's features — for example creating client records, assigning worksheets, enabling response sharing, and requesting export or deletion. The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes UK GDPR.
6.2 Security measures
- All data encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Row-level security (RLS) enforced at database level — each therapist can only access their own data
- PII stripping before any data is sent to AI sub-processors
- Strict Content Security Policy with per-request nonces
- Primary database hosted in AWS eu-west-2 (London)
For full details, see our Security page.
6.3 Breach notification
In the event of a personal data breach, the Processor will notify the Controller without undue delay and in any case within 72 hours of becoming aware of the breach, providing the nature of the breach, categories and approximate numbers of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
6.4 Confidentiality
All persons authorised to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
6.5 Assistance with data subject rights
The Processor will assist the Controller in responding to data subject access requests, rectification, erasure (right to be forgotten under GDPR Article 17), and data portability requests. Clients can independently request deletion through their secure data portal.
6.6 Assistance with security, breach notification, DPIAs and prior consultation
Taking into account the nature of the processing and the information available to it, the Processor will assist the Controller in ensuring compliance with the Controller's obligations under Articles 32 to 36 of UK GDPR — security of processing, notification of personal data breaches to the Information Commissioner's Office and to affected data subjects, data protection impact assessments (DPIAs), and prior consultation with the ICO. This includes providing the information in this DPA, on our Security page and in our DTAC self-assessment, and responding to reasonable requests for further information needed for the Controller's own DPIA.
6.7 Data return & deletion
Upon termination of the agreement, the Processor will, at the Controller's choice, return all personal data or delete it permanently. Deleted data is purged after a 90-day retention window to allow for recovery from accidental deletion.
7. Sub-processors
The Controller authorises the Processor to engage the following sub-processors. The Processor will give the Controller at least 30 days' notice of any intended addition or replacement of a sub-processor, by email to the account email address and by updating the list on this page, giving the Controller the opportunity to object before the change takes effect.
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication & file storage | UK (London, AWS eu-west-2) |
| Vercel | Application hosting & CDN | Global edge (US/EU) |
| Stripe | Payment processing | US / EU |
| Resend | Transactional email | US |
| Anthropic | AI worksheet generation (PII-stripped input only) | US |
| Sentry | Error monitoring (no clinical data) | US |
| Meta (Facebook) Pixel | Advertising-performance measurement — loaded only with your cookie consent | US |
| Vercel Web Analytics | Aggregate usage analytics — loaded only with your cookie consent | US / EU |
| Ayrshare | Publishing our own marketing/blog posts to social media (no client or personal data) | US |
8. International transfers
The primary database is hosted in the UK (AWS eu-west-2, London). Application compute and CDN are provided by Vercel's global edge network. Where personal data is transferred to sub-processors outside the UK/EEA (Stripe, Resend, Anthropic, Sentry, and — only with cookie consent — the Meta Pixel and Vercel Web Analytics), such transfers are governed by Standard Contractual Clauses (SCCs) or equivalent safeguards under UK GDPR.
Data sent to Anthropic for AI processing is PII-stripped before transmission. Clinical worksheet response data is not transferred outside the UK database.
9. Data subject rights
Formulate supports the following data subject rights:
- Right of access: Clients can always see their homework completion status and, where their therapist has enabled response sharing, view their submitted responses via their secure data portal.
- Right to erasure: Clients can request deletion via their portal. Therapists can delete client records at any time. Deleted data is purged after 90 days.
- Right to data portability: Therapists can export individual worksheet responses as PDFs; clients can export their own homework responses from their secure portal.
- Right to rectification: Therapists can correct the client records they hold (client labels and case details). Client-submitted worksheet responses are deliberately not editable in place — by the therapist or anyone else — once submitted: the platform stores them read-only as a record-integrity safeguard, so what the client wrote, and when, is preserved. Corrections are handled by annotation instead: therapists can attach dated feedback to a submission, and each feedback addition or removal is recorded in the platform's audit log with the acting user and timestamp. Where the content of a response itself needs to change, the therapist can assign a fresh worksheet for the client to complete, or delete the record (see erasure above).
10. Audit rights
The Controller has the right to audit the Processor's compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and allow for, and contribute to, audits and inspections conducted by the Controller or an authorised auditor, subject to reasonable notice and confidentiality obligations.
11. Termination
This DPA remains in effect for the duration of the Controller's use of the Formulate platform. Upon termination, Section 6.7 (Data return & deletion) applies. Obligations relating to confidentiality and data protection survive termination.
12. Requesting a countersigned copy
Institutional customers and information governance teams often need an executed copy of this DPA rather than a web page. To request a countersigned copy, use our contact form (category “Data protection / security”) or email formulatetools@outlook.com, including your organisation name and the account email address the agreement should cover.
You can also print this page or save it as a PDF using the button at the top — the printed copy carries the version number and date, so it can be filed as a dated artefact of the terms in force.
Version history
This agreement is versioned so the Controller can evidence which terms applied at a given time.
- Version 1.1 — July 2026: Added the documented-instructions clause (§6.1, UK GDPR Art. 28(3)(a)) and the Articles 32–36 assistance clause (§6.6); stated the 30-day email notice channel for sub-processor changes (§7); reworded §9 rectification — client-submitted responses are read-only once submitted, with corrections by audit-logged annotation; added the countersigned-copy request route (§12) and the print/save-as-PDF affordance; completed the registered address.
- Version 1.0 — June 2026: First published version.
Contact
For questions about this DPA or to exercise any rights under it, contact us at formulatetools@outlook.com or use the contact form (category “Data protection / security”).