Legal
Data Processing Agreement
- Version:
- Draft 1.0
- Effective:
- Upon incorporation into an Order or SaaS acceptance
- Last updated:
- 9 September 2026
- Operator:
- MTX STUDIO Ltd trading as Plinical
- Company no.
- 15856187
- Registered office:
- Princess House The Square, 3rd Floor, Shrewsbury, Shropshire, England, SY1 1JZ
DRAFT / REVIEW-READY — not approved. This public Data Processing Agreement text is provided so prospective clinic customers can evaluate contracting terms during review. It must not be labelled or treated as a final approved legal DPA until owner/legal sign-off. The final executed or owner-approved DPA prevails if it differs.
1. Parties
Processor (“Plinical” / “Supplier”): MTX STUDIO Ltd, trading as Plinical, company no. 15856187, registered office Princess House The Square, 3rd Floor, Shrewsbury, Shropshire, England, SY1 1JZ.
Controller (“Customer”): the clinic or healthcare business identified in the applicable Order / online acceptance / SaaS Agreement.
2. Roles
Customer is controller for clinic/patient records and clinic-instructed processing.
MTX STUDIO Ltd is processor for that personal data when providing the Service.
MTX is controller for its own Website, business contacts, subscription administration, support, security and compliance records (as described in the Privacy Notice) — outside this DPA’s processor scope unless the parties agree otherwise.
3. Subject matter, duration, nature, purpose
Subject matter: Provision of the Plinical clinic practice-management SaaS.
Duration: Term of the SaaS Agreement plus the post-termination deletion/return period.
Nature: Hosting, storage, retrieval, transmission, display, backup, security logging, support access as instructed.
Purpose: Enable Customer to manage bookings, patients, clinical documentation, consent, referrals, clinic finance, and related clinic operations.
4. Data subjects
Patients (including children where the clinic lawfully treats them); clinic staff (admins, clinicians, receptionists); business contacts of the clinic as entered by the Customer.
5. Categories of personal data
Identity and contact details; appointment and diary data; clinical notes, assessments, treatment plans; consent/signatures; referrals; clinic invoices and payments metadata; communications content; files/PDFs; exports; technical identifiers necessary to operate the Service.
6. Special-category / health data
Health and special-category data may be processed where the Customer enters it. Customer is responsible for its lawful bases (including UK GDPR Art. 9 where applicable).
7. Documented instructions
Processor processes only on documented instructions from the Customer (SaaS Agreement, Order, configuration in the Service, and written instructions), unless UK law requires otherwise.
8. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations.
9. Security measures
Implement appropriate technical and organisational measures. Engineering baseline includes tenant isolation, RBAC, encryption at rest for designated fields, private object storage, CSRF protections, rate limiting, log sanitisation, and backups. See the Privacy Notice and related security materials for further detail.
10. Subprocessors
Customer authorises use of subprocessors listed in the subprocessor schedule / Privacy Notice categories. Processor shall impose equivalent data-protection obligations. Material changes will be notified per the notice period agreed with legal counsel.
11. International transfers
Transfers outside the UK only with appropriate safeguards (adequacy, IDTA/Addendum/SCCs, or other lawful mechanism), consistent with the Privacy Notice.
12. Assistance
Assist Customer with data-subject rights, security incidents, DPIAs and regulator engagement, taking into account the nature of processing and information available to Processor.
13. Security incidents
Notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer data, with information reasonably available to assist Customer’s obligations.
14. Deletion / return
On termination: Customer retrieval window; thereafter active deletion of Customer personal data from production systems; backups removed through the normal cycle (see Privacy Notice for retrieval and backup cycle statements).
15. Audits / information
Make available information necessary to demonstrate compliance and allow audits as agreed in the final DPA.
16. Schedules
Schedule 1 — Processing details
Schedule 2 — Security measures
Schedule 3 — Subprocessors
Schedule 4 — Transfer mechanisms
Related public documents: Privacy Notice (/privacy), SaaS Terms (/saas-terms), Cookie Policy (/cookies).