← CareFlow AI home

Data Processing Agreement

CareFlow AI, a product of AHG International · Version 1.0 · 4 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between AHG International ("the Processor") and the customer organisation that subscribes to CareFlow AI ("the Controller"). It takes effect when the Controller creates a CareFlow AI account or, if requested, when countersigned. A countersigned copy is available on request from kiranaudit@mac.com.

1. Definitions and scope

"UK GDPR", "personal data", "processing", "data subject", "personal data breach" and related terms have the meanings given in the UK General Data Protection Regulation and the Data Protection Act 2018. This DPA applies to all personal data the Processor processes on the Controller's behalf in providing CareFlow AI (the "Service").

2. Roles and instructions

  1. The Controller is the data controller of all content its managers and staff put into the Service; the Processor processes that data only as a processor.
  2. The Processor shall process personal data only on the Controller's documented instructions, which are: to provide the Service as described in Annex A (including automated transcription, translation, summarising and urgency triage of notes, and the sending of prompt, task and alert emails), unless required to do otherwise by UK law — in which case the Processor will inform the Controller before processing, unless the law prohibits it.
  3. The Processor will immediately inform the Controller if, in its opinion, an instruction infringes UK data protection law.

3. Confidentiality

The Processor ensures that every person it authorises to process the Controller's data is bound by a duty of confidentiality, contractual or statutory.

4. Security (Article 32)

The Processor implements and maintains the technical and organisational measures in Annex C, including encryption in transit and at rest, per-organisation data isolation, individually attributed audit logging, and revocable tokenised staff access. The Processor may update these measures provided security is not materially reduced.

5. Sub-processors

  1. The Controller gives general written authorisation for the sub-processors listed in Annex B.
  2. The Processor will give the Controller at least 14 days' notice by email before adding or replacing a sub-processor. If the Controller reasonably objects on data-protection grounds and no resolution is found, the Controller may terminate the affected Service with a pro-rata refund of prepaid fees.
  3. The Processor imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains fully liable to the Controller for their performance.

6. Data subject rights

Taking into account the nature of the processing, the Processor will assist the Controller with appropriate technical and organisational measures to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts the Processor directly, the Processor will forward the request to the Controller without undue delay and will not respond substantively except on the Controller's instruction.

7. Personal data breach

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, providing sufficient information for the Controller to meet its own notification obligations to the ICO and data subjects, and will cooperate in investigating and mitigating the breach.

8. Assistance

The Processor will assist the Controller, taking into account the nature of the processing and the information available to it, with data protection impact assessments, prior consultations with the ICO, and the Controller's security obligations under Articles 32–36 UK GDPR.

9. International transfers

Personal data is hosted in the United Kingdom (AWS London, eu-west-2). Limited processing by the sub-processors in Annex B takes place outside the UK (transcription, AI triage, email delivery, payments). All such transfers are made under the UK International Data Transfer Addendum or UK Addendum to the EU Standard Contractual Clauses and, where applicable, the UK–US Data Bridge. OpenAI and Anthropic process note content under their API terms and do not use it to train models.

10. Deletion and return

On termination of the Service, the Processor will, at the Controller's choice, return the Controller's personal data in a commonly used format or delete it, and will delete existing copies within 90 days of contract end, save where UK law requires continued storage (e.g. accounting records). During the subscription, notes are archived rather than deleted inside the app so that the Controller's audit trail remains intact; this is a feature of the Service and an instruction of the Controller.

11. Audit and information

The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will allow and contribute to audits, including inspections, conducted by the Controller or its mandated auditor, on at least 14 days' written notice, no more than once per year (except after a personal data breach), during business hours, and without access to other customers' data.

12. Liability and duration

This DPA is effective for as long as the Processor processes personal data on the Controller's behalf. Liability under this DPA is subject to the limitations of liability in the parties' main service agreement.

Annex A — Details of processing

Subject matterProvision of the CareFlow AI staff voice-note capture, triage, task and audit service
DurationThe term of the Controller's subscription plus the deletion period in clause 10
Nature and purposeCollection, storage, transcription, translation, summarising, urgency triage, task allocation, notification emails, audit logging
Categories of data subjectsThe Controller's managers and staff; residents and other individuals mentioned in notes
Categories of personal dataNames, work contact details, roles, languages; voice recordings, transcripts, translations, summaries, task instructions and resolutions; manager action logs
Special category dataHealth and care information about residents or staff, where included in the content of notes recorded by the Controller's staff

Annex B — Authorised sub-processors

Sub-processorProcessingLocation
Supabase (on AWS)Database, voice-file storage, application functionsUK (London, eu-west-2)
VercelWeb page hosting (no note content stored)Global CDN
OpenAISpeech-to-text transcriptionUS
AnthropicTranslation, summarising, urgency triageUS
ResendTransactional email deliveryUS/EU
StripeSubscription payment processing (Controller billing data only)US/EU

Annex C — Technical and organisational measures

Questions about this DPA, or need a countersigned copy for your records or your CQC evidence pack? Email kiranaudit@mac.com.