Quzek

Data Processing Agreement

Last updated: July 2026.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Quzek ("Processor") and the practice or organisation using the Service ("Controller", "you"). It describes how Quzek processes personal data on your behalf and reflects the requirements of the GDPR, the UK GDPR, and comparable data-protection laws. A signed counterpart is available on request at [email protected]; where you need one, the signed version prevails over this online text.

Capitalised terms not defined here have the meaning given in our Terms of Service.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority" and "Personal Data Breach" have the meanings given in applicable data-protection law. "Customer Data" means the Personal Data you enter into the Service. "Sub-processor" means a third party engaged by Quzek to process Customer Data.

2. Roles of the parties

For Customer Data, you are the Controller (or a processor acting for another controller) and determine the purposes and means of processing; Quzek is the Processor and processes Customer Data only on your documented instructions. This DPA does not apply to data for which Quzek is itself the controller (such as your account and billing data), which is governed by our Privacy Policy.

3. Subject matter and duration

The subject matter is the provision of the Service. Processing continues for the duration of your subscription and until deletion or return of Customer Data in accordance with this DPA. The nature, purpose, types of Personal Data and categories of Data Subjects are set out in Annex I below.

4. Our obligations as Processor

Quzek will: (a) process Customer Data only on your documented instructions, including as set out in the Terms and this DPA, unless required otherwise by law (in which case we will inform you unless legally prohibited); (b) ensure that personnel authorised to process Customer Data are bound by confidentiality; (c) implement and maintain the technical and organisational measures described in Annex II; (d) assist you, taking into account the nature of processing, in responding to Data Subject requests and in meeting your obligations regarding security, breach notification and data-protection impact assessments; and (e) make available information reasonably necessary to demonstrate compliance with this DPA.

5. Confidentiality

We limit access to Customer Data to personnel who need it to provide, support or secure the Service, and who are subject to appropriate confidentiality obligations.

6. Security measures

Quzek maintains appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access — including per-practice database isolation, encryption in transit and at rest (with field-level encryption of sensitive clinical notes), role-based access control, two-factor authentication, automatic session logoff, audit logging, private file storage and encrypted backups. A summary is set out in Annex II and on our Security page.

7. Sub-processors

You provide a general authorisation for Quzek to engage Sub-processors to provide the Service (for example hosting, email and SMS delivery, payment processing, and monitoring). We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We maintain a list of Sub-processors (available on request) and will give you reasonable notice of any intended addition or replacement, giving you the opportunity to object on reasonable data-protection grounds.

8. Assistance with Data Subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). The Service includes self-service tools — a complete data export and a right-to-erasure (anonymisation) action per client — that enable you to respond directly. If we receive a request directly from one of your Data Subjects, we will refer them to you.

9. Personal Data Breach notification

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, and will provide information reasonably available to us to help you meet your own notification obligations to Supervisory Authorities and Data Subjects (for example within the GDPR 72-hour window, or under the Australian NDB scheme or the HIPAA Breach Rule). We will take reasonable steps to contain and remediate the breach.

10. Data protection impact assessments

Taking into account the nature of processing and information available to us, we will provide reasonable assistance with data-protection impact assessments and prior consultations with Supervisory Authorities that you are required to carry out.

11. International transfers

Where processing of Customer Data involves a transfer to a country without an adequacy decision, the parties rely on appropriate safeguards — including the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum — which are incorporated by reference and completed by the details in Annex I. For US healthcare, a Business Associate Agreement (BAA) is available on request.

12. Deletion and return of data

On termination or expiry of the Service, and at your choice, we will delete or return Customer Data, and delete existing copies, except to the extent applicable law requires retention. You may export your Customer Data for a reasonable period after termination; thereafter it is deleted from active systems in the ordinary course, subject to any legal retention requirements and routine backup cycles.

13. Audit

We will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, frequency limits, and safeguards to protect the security and confidentiality of other customers' data. Where available, we may satisfy audit requests by providing third-party reports or security documentation.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

Annex I — Details of processing

Categories of Data Subjects: your staff and users; your clients or patients; and other individuals whose data you enter (such as emergency contacts or referrers).

Categories of Personal Data: contact and identity details; appointment and scheduling data; clinical, treatment and intake information (which may include health / special-category data); consent records; invoices and payment-related data; and communications.

Nature and purpose of processing: hosting, storing, transmitting and displaying Customer Data to provide scheduling, online booking, reminders, intake and consent, clinical records, invoicing, payments and related functionality, plus support and security.

Duration: for the term of the subscription and until deletion or return as described above.

Annex II — Technical and organisational measures

Contact

Questions about this DPA, or requests to enter into a signed version or a Business Associate Agreement, can be sent to [email protected].