Data Processing Addendum
Last updated: 18 July 2026.
This addendum applies when a clinic, charity, employer, or other organisation (the "Controller") instructs its members, patients, or staff to use Symply and where BranchX Limited ("Processor") processes personal or health data on the Controller's instructions.
1. Subject and duration
Processing covers voice recordings, transcripts, medication and symptom data, evidence uploads, care circle notes, and account metadata, for as long as the Controller and its users hold an active account.
2. Nature and purpose
Storage, structuring, transcription (opt-in), retrieval, sharing to authorised recipients, and deletion — all under the Controller's and end-user's instructions issued through the Symply app.
3. Categories of data and data subjects
Personal identifiers (email, name), special-category health information (symptoms, medications, clinical documents, recordings). Data subjects: end-users invited or authorised to use Symply by the Controller.
4. Processor obligations
- Process only on documented Controller instructions.
- Ensure staff authorised to access data are under confidentiality obligations.
- Apply the technical and organisational measures described on the Security page.
- Assist the Controller with data subject requests and impact assessments.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
- On termination, delete or return Controller data unless retention is required by law.
5. Sub-processors
The current list of authorised sub-processors is on the sub-processors page. We will provide reasonable prior notice of new sub-processors so the Controller can object.
6. International transfers
Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
7. Audit
We will respond to reasonable written audit requests with the most recent security documentation, sub-processor list, and, where necessary, a mutually agreed audit under confidentiality.
8. Signature
To countersign a copy of this addendum for your organisation, email us.