Data Processing Agreement
Last updated: July 2026.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Quzek ("Processor") and the practice or organisation using the Service ("Controller", "you"). It describes how Quzek processes personal data on your behalf and reflects the requirements of the GDPR, the UK GDPR, and comparable data-protection laws. A signed counterpart is available on request at [email protected]; where you need one, the signed version prevails over this online text.
Capitalised terms not defined here have the meaning given in our Terms of Service.
1. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority" and "Personal Data Breach" have the meanings given in applicable data-protection law. "Customer Data" means the Personal Data you enter into the Service. "Sub-processor" means a third party engaged by Quzek to process Customer Data.
2. Roles of the parties
For Customer Data, you are the Controller (or a processor acting for another controller) and determine the purposes and means of processing; Quzek is the Processor and processes Customer Data only on your documented instructions. This DPA does not apply to data for which Quzek is itself the controller (such as your account and billing data), which is governed by our Privacy Policy.
3. Subject matter and duration
The subject matter is the provision of the Service. Processing continues for the duration of your subscription and until deletion or return of Customer Data in accordance with this DPA. The nature, purpose, types of Personal Data and categories of Data Subjects are set out in Annex I below.
4. Our obligations as Processor
Quzek will: (a) process Customer Data only on your documented instructions, including as set out in the Terms and this DPA, unless required otherwise by law (in which case we will inform you unless legally prohibited); (b) ensure that personnel authorised to process Customer Data are bound by confidentiality; (c) implement and maintain the technical and organisational measures described in Annex II; (d) assist you, taking into account the nature of processing, in responding to Data Subject requests and in meeting your obligations regarding security, breach notification and data-protection impact assessments; and (e) make available information reasonably necessary to demonstrate compliance with this DPA.
5. Confidentiality
We limit access to Customer Data to personnel who need it to provide, support or secure the Service, and who are subject to appropriate confidentiality obligations.
6. Security measures
Quzek maintains appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access — including per-practice database isolation, encryption in transit and at rest (with field-level encryption of sensitive clinical notes), role-based access control, two-factor authentication, automatic session logoff, audit logging, private file storage and encrypted backups. A summary is set out in Annex II and on our Security page.
7. Sub-processors
You provide a general authorisation for Quzek to engage Sub-processors to provide the Service (for example hosting, email and SMS delivery, payment processing, and monitoring). We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We maintain a list of Sub-processors (available on request) and will give you reasonable notice of any intended addition or replacement, giving you the opportunity to object on reasonable data-protection grounds.
8. Assistance with Data Subject rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). The Service includes self-service tools — a complete data export and a right-to-erasure (anonymisation) action per client — that enable you to respond directly. If we receive a request directly from one of your Data Subjects, we will refer them to you.
9. Personal Data Breach notification
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, and will provide information reasonably available to us to help you meet your own notification obligations to Supervisory Authorities and Data Subjects (for example within the GDPR 72-hour window, or under the Australian NDB scheme or the HIPAA Breach Rule). We will take reasonable steps to contain and remediate the breach.
10. Data protection impact assessments
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with data-protection impact assessments and prior consultations with Supervisory Authorities that you are required to carry out.
11. International transfers
Where processing of Customer Data involves a transfer to a country without an adequacy decision, the parties rely on appropriate safeguards — including the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum — which are incorporated by reference and completed by the details in Annex I. For US healthcare, a Business Associate Agreement (BAA) is available on request.
12. Deletion and return of data
On termination or expiry of the Service, and at your choice, we will delete or return Customer Data, and delete existing copies, except to the extent applicable law requires retention. You may export your Customer Data for a reasonable period after termination; thereafter it is deleted from active systems in the ordinary course, subject to any legal retention requirements and routine backup cycles.
13. Audit
We will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, frequency limits, and safeguards to protect the security and confidentiality of other customers' data. Where available, we may satisfy audit requests by providing third-party reports or security documentation.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
Annex I — Details of processing
Categories of Data Subjects: your staff and users; your clients or patients; and other individuals whose data you enter (such as emergency contacts or referrers).
Categories of Personal Data: contact and identity details; appointment and scheduling data; clinical, treatment and intake information (which may include health / special-category data); consent records; invoices and payment-related data; and communications.
Nature and purpose of processing: hosting, storing, transmitting and displaying Customer Data to provide scheduling, online booking, reminders, intake and consent, clinical records, invoicing, payments and related functionality, plus support and security.
Duration: for the term of the subscription and until deletion or return as described above.
Annex II — Technical and organisational measures
- Per-practice database isolation (strong multi-tenant separation).
- Encryption in transit (TLS) and at rest, incl. field-level encryption of sensitive clinical notes.
- Role-based access control and least-privilege administration.
- Two-factor authentication and automatic session timeout.
- Append-only audit logging of access to sensitive records.
- Private file storage served only to authenticated, authorised users.
- Scheduled, encryptable backups and documented recovery.
- Secure development practices, dependency management and change review.
- Incident-response and breach-notification processes.
- Confidentiality obligations on personnel and sub-processors.
Contact
Questions about this DPA, or requests to enter into a signed version or a Business Associate Agreement, can be sent to [email protected].