Folelse
Legal

Data Processing Agreement

Version 1.0 — Effective 9 August 2026

This DPA forms part of the Folelse Subscriber Agreement and governs how we process personal data on your behalf as data processor under UK GDPR Article 28. It mirrors the binding version you accept in-product at app.folelsegovernance.co.uk/legal/dpa.

What this DPA covers

  • UK GDPR Article 28 compliant — covers all mandatory processor obligations
  • International transfers covered by the UK Extension to the EU–US Data Privacy Framework (Stripe) and the UK Addendum to the EU SCCs (WorkOS)
  • Sub-processor list (Microsoft Azure, WorkOS, Stripe) with 30 days’ change notice
  • Technical and Organisational Measures (TOMs) schedule (Article 32)
  • NHS-specific: special-category (health) data covered in the processing details
  • Personal data breach notification within 48 hours

Need a signed copy?

Enterprise subscribers can request a countersigned PDF DPA for their records. Contact our legal team at [email protected].

Request signed DPA

Data Controller

The Customer

The organisation entering into a subscription agreement with Folelse

Data Processor

Folelse Ltd

Co. No. 17132576 · Incorporated 1 April 2026

6th Floor, 37 Lombard Street, London, EC3V 9BQ, United Kingdom

1. Definitions and roles

1.1 Terms "personal data", "special category data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings in UK Data Protection Law (the UK GDPR as retained by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018).

1.2 As between the parties, the Customer is the controller and Folelse is the processor in respect of the personal data described in Schedule 1.

1.3 This DPA applies to Folelse's processing of Customer personal data and prevails over any conflicting data-protection term in the Subscriber Agreement.

2. Processing on documented instructions

Folelse will process Customer personal data only on the Customer's documented instructions (including this DPA, the Subscriber Agreement, and use of the Service's features), unless required by law, in which case Folelse will inform the Customer unless legally prohibited.

3. Confidentiality of personnel

Folelse ensures persons authorised to process Customer personal data are under an appropriate duty of confidentiality.

4. Security (Article 32)

Folelse implements appropriate technical and organisational measures as set out in Schedule 2, appropriate to the risk of processing special-category (health) data.

5. Sub-processing (Article 28(2),(4))

5.1 The Customer gives general authorisation for Folelse to engage the sub-processors listed in Schedule 3 (currently Microsoft Azure, WorkOS, Stripe).

5.2 Folelse imposes on each sub-processor data-protection obligations equivalent to those in this DPA and remains liable for its sub-processors.

5.3 Folelse will give the Customer at least 30 days' notice of any intended change of sub-processor (via the sub-processor notification list / in-product), during which the Customer may reasonably object; if an objection cannot be resolved the Customer may terminate the affected Service.

6. Data subject rights

Taking account of the nature of processing, Folelse will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (Articles 12–23), without undue delay and in any event within 10 business days of the Customer's request.

7. Personal data breach

7.1 Folelse will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer personal data.

7.2 The notification will include the information the Customer reasonably needs to meet its own Article 33/34 obligations.

7.3 It is the Customer's responsibility, as controller, to notify the ICO/data subjects where required.

8. DPIAs and prior consultation

Folelse will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultation (Articles 35–36), taking account of the nature of processing and information available to Folelse.

9. International transfers

9.1 Folelse will not transfer Customer personal data outside the UK except in compliance with UK Data Protection Law.

9.2 Where sub-processors process data outside the UK (currently Stripe and WorkOS, United States), the transfer is made under an appropriate safeguard as follows: • Stripe — the transfer relies on the UK Extension to the EU–US Data Privacy Framework (the "UK–US data bridge"), Stripe being certified under the EU–US Data Privacy Framework; and • WorkOS — the transfer is made under the UK Addendum to the EU Standard Contractual Clauses.

9.3 Folelse keeps the transfer safeguard relied on for each sub-processor under review and will update it if a sub-processor's certification or the applicable safeguard changes.

10. Deletion or return

On termination of the relevant Service, Folelse will, at the Customer's choice, delete or return Customer personal data within 30 days and delete existing copies, save where storage is required by law. This is reflected in the Subscriber Agreement §14 export window.

11. Audits and information

Folelse will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits. Folelse may satisfy this through its compliance documentation and security alignment statements (see Schedule 2) where available.

12. Liability

Liability under this DPA is subject to the limitations and exclusions in the Subscriber Agreement §11, except where UK Data Protection Law requires otherwise.

13. Term and governing law

This DPA lasts as long as Folelse processes Customer personal data and is governed by the law of England and Wales, with the exclusive jurisdiction of the courts of England and Wales.

Schedule 1 – Details of processing (Article 28(3))

Subject matter: provision of the Folelse compliance platform.

Duration: the Subscription Term plus the deletion/return period.

Nature and purpose: hosting, storage and processing of compliance records so the Customer can manage DSPT, ROPA/Article 30, DPIAs, risk, assets, suppliers, policies, and related workflows.

Type of personal data: identifiers and contact details of the Customer's staff/Authorised Users and the individuals recorded in the Customer's compliance data; and special category data (health data) where the Customer chooses to record it.

Categories of data subjects: the Customer's staff, contractors, and the data subjects referenced in the Customer's compliance records (which may include patients/service users).

Schedule 2 – Technical and Organisational Measures (Article 32)

  • Encryption in transit (TLS) and at rest (AES-256) on Azure UK South.
  • UK data residency: all Customer personal data stored and processed in the UK (Azure UK South); see the sub-processor list for the only non-UK transfers.
  • Access control: role-based access, least privilege, MFA for Folelse staff; Managed-Identity (passwordless) database access; no standing Folelse access to Customer-authored data (time-boxed, justified, audited break-glass only).
  • Malware scanning on upload (Microsoft Defender for Storage); immutable, hash-chained audit logging.
  • Monitoring/telemetry in-region (Application Insights), with PII scrubbing.
  • Security governance: Folelse's information-security practices are aligned to the principles of ISO 27001:2022 and Cyber Essentials.

Schedule 3 – Authorised sub-processors

  • Microsoft Azure — cloud hosting, PostgreSQL database, blob storage, key management, transactional email (ACS), telemetry. United Kingdom (UK South). No cross-border transfer.
  • WorkOS — authentication / SSO / directory sync. United States. Cross-border — UK Addendum to EU SCCs (see clause 9.2).
  • Stripe — payment processing. United States. Cross-border — UK Extension to the EU–US Data Privacy Framework (see clause 9.2).

Execution

This DPA is incorporated into the Folelse Terms of Use. By accepting the Terms of Use, the Controller agrees to this DPA. No further signature is required for standard subscription tiers. Enterprise subscribers may request a manually executed version at [email protected].

Data Controller (Customer)

Signed

Name

Title

Date

Data Processor (Folelse Ltd)

Signed

Name

Title

Date