Data Processing Agreement
Last updated: 8 September 2026 · Takes effect: 8 September 2026
Version: 2026-09-08_v2 Effective: 8 September 2026 Processor: DJG Media Limited (trading as Brigid), CRO No. 762838, Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland Governing law: the laws of Ireland · Supervisory authority: Data Protection Commission (dataprotection.ie)
This Agreement is made under Article 28 of Regulation (EU) 2016/679 (GDPR) and the Data Protection Act 2018 (Ireland). It is concluded in electronic form, which Article 28(9) permits, and takes effect when an authorised representative of the Controller accepts it and the Controller's legal identity is recorded.
1. Parties and roles
Controller: the legal entity named in the acceptance record, being the clinic or practice subscribing to Brigid.
Processor: DJG Media Limited (trading as Brigid), CRO No. 762838, of Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland.
The Controller determines the purposes and means of processing patient personal data. The Processor processes that data only on the Controller's behalf.
2. Subject matter, duration, nature and purpose (Art. 28(3))
Subject matter: provision of the Brigid practice-management platform and its connected services.
Duration: for the term of the subscription, plus any retention period instructed by the Controller or required by law. Each record category follows the retention schedule agreed with the Controller; the working schedule remains a launch gate and this Agreement does not impose one universal period across all clinical and security records.
Nature and purpose: storing, organising, retrieving and transmitting patient and staff records so the Controller can deliver and administer healthcare.
Types of personal data: identification and contact data; special-category health data including clinical notes, medications, allergies, conditions, results, referrals and prescriptions; billing data; clinician and staff records.
Categories of data subjects: the Controller's patients, clinicians and administrative staff.
3. Processing only on documented instructions (Art. 28(3)(a))
The Processor processes personal data only on the Controller's documented instructions, including as to transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, the Processor informs the Controller before processing, unless that law prohibits it on important grounds of public interest.
The Controller's use of the platform in the ordinary course constitutes documented instructions. Further instructions may be given in writing.
The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law.
4. Confidentiality of personnel (Art. 28(3)(b))
The Processor ensures that every person it authorises to process personal data — employee, contractor, or sub-processor personnel — is bound to confidentiality before access is granted, either by a written undertaking in the form published by the Processor or by an appropriate statutory or professional duty of confidence. The Processor maintains a register of the persons so authorised and of the instrument binding each, and makes that register available to the Controller on request.
Access is granted only where necessary for that person's role, is withdrawn when the role changes or ends, and is logged. The confidentiality obligation survives the end of that person's engagement and the end of this Agreement.
5. Security of processing (Art. 28(3)(c), Art. 32)
The Processor implements and maintains appropriate technical and organisational measures, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons. These include:
- encryption of personal data in transit and at rest;
- tenant isolation enforced at the database layer, so one Controller's data is not accessible to another;
- role-based access control and unique user identification;
- logging of access to patient records, with an append-only audit trail;
- daily backups of the primary database, retained on managed infrastructure within the European Union on a rolling basis for approximately seven to eight days, from which the database can be restored to the most recent backup; the Processor's stored files are held on durable object storage that is resilient to infrastructure failure but is not point-in-time recoverable. A scheduled copy of those stored files to backup buckets within the same European Union project was set up on 3 September 2026 and switched on with the next deployment; its first restore drill will be recorded in the testing record maintained under this clause;
- a written record of the technical and organisational measures the Processor has tested internally, the method used and the date, which the Processor maintains and makes available to the Controller on request; and independent testing of those measures, scheduled to take place after the Processor's first clinic is live, the outcome of which will be added to that record.
The Processor maintains that record, states in it plainly which measures have not yet been tested and by whom, and makes it available to the Controller on request.
6. Sub-processors (Art. 28(2), 28(3)(d), 28(4))
The Controller grants general written authorisation for the Processor to engage sub-processors, subject to this clause.
The Processor publishes a sub-processor inventory covering active, disabled, historical and candidate routes. Appearance in that inventory is not itself evidence that a provider is authorised for a given Controller: the authorised set is the schedule agreed with that Controller.
The Processor gives the Controller at least 30 days' written notice before adding or replacing any sub-processor that processes its data. The Controller may object in writing within that period. Where an objection cannot reasonably be accommodated, the Controller may terminate the subscription without penalty.
The Processor imposes on each sub-processor, by contract, data protection obligations no less protective than those in this Agreement, and remains fully liable to the Controller for the performance of that sub-processor's obligations.
7. Assistance with data subject rights (Art. 28(3)(e))
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data subject rights under Chapter III — access, rectification, erasure, restriction, portability and objection.
Where the Processor receives such a request directly from a data subject, it does not respond substantively but refers the data subject to the Controller and informs the Controller without undue delay.
8. Assistance with Articles 32 to 36 (Art. 28(3)(f))
The Processor assists the Controller in ensuring compliance with the obligations in Articles 32 to 36, taking into account the nature of processing and the information available to it. This includes security of processing, personal data breach notification, communication to data subjects, data protection impact assessments, and prior consultation.
9. Personal data breach (Art. 33(2))
The Processor notifies the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting personal data processed on the Controller's behalf. Notice is given by the Processor's named incident lead or deputy to the contacts the Controller has recorded for this purpose. The Processor maintains a written breach-response procedure that names an incident lead and a deputy, tests the route by which they are reached at least once a year, and records each test.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not available at once, it is provided in phases without further undue delay.
10. Deletion or return of data (Art. 28(3)(g))
At the end of the provision of services, the Controller chooses whether the Processor deletes or returns the personal data processed on its behalf. The Processor acts on that instruction and deletes existing copies, except to the extent that Union or Member State law requires continued storage.
Three periods govern this and are set in the order form executed with each Controller, not fixed here:
- the export window during which the Controller may retrieve its data;
- the active-system deletion deadline after that window closes;
- the backup-expiry process, including when backup copies lapse.
No default period is represented as approved by this published text. Production patient data is not accepted until those three are agreed in writing with the Controller, because a deletion commitment that has not been costed against the actual backup rotation is a promise made in advance of knowing whether it can be kept.
Data returned is provided in a structured, commonly used, machine-readable format. Where law requires retention beyond the agreed periods, the Processor tells the Controller which data is retained, on what legal basis, and for how long.
11. Audit and inspection (Art. 28(3)(h))
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations in Article 28, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.
Audits are conducted on reasonable notice, during business hours, no more than once in any twelve-month period unless a personal data breach or a supervisory authority requires otherwise, and subject to confidentiality.
12. International transfers (Chapter V)
Personal data is stored at rest within the European Union, except where the Controller enables a route whose entry in the published sub-processor inventory states a different storage location; in that case the transfer mechanism recorded for that route applies. Where processing by a sub-processor involves a transfer to a third country, the Processor ensures an appropriate transfer mechanism under Chapter V — an adequacy decision, Standard Contractual Clauses, or another lawful mechanism — together with any supplementary measures required, and records the basis for each transfer.
13. Precedence and variation
This Agreement forms part of the subscription between the parties. In the event of conflict between this Agreement and the Terms of Service in respect of the processing of personal data, this Agreement prevails.
The Processor may issue a new version of this Agreement on reasonable notice. Continued use of the service after a new version takes effect does not by itself constitute acceptance of that version where the change materially reduces the Controller's protections; in that case the Processor seeks a fresh acceptance.
14. Execution
Accepted in electronic form under Article 28(9). The acceptance record identifies the Controller's legal entity, its registration number and registered address, the name and role of the authorised signatory, the date and time of acceptance, and the version of this Agreement accepted.
This page renders the agreement text itself, not a summary of it. The version accepted by a clinic is fingerprinted, so the exact wording agreed can always be established:
SHA-256: a87c9f6f681b2c59ca6b6d676936849b1b6fdafb3ec7b818bdcd0aa9df9a24a8
Source: docs/legal/DPA_2026-09-08_v2.md