Data Processing Agreement
Last updated: 28 September 2026
Published update — not yet the in-app acceptance version. This edition awaits legal review and activation. Existing acceptance records retain their original wording. Read the version currently linked from the app.
Version: 2026-09-28_v5 Publication date: 28 September 2026 Application: This updated edition is published for review. It is not yet the version offered for in-app acceptance. It does not replace an existing agreement merely by publication. Processor: DJG Media Limited (trading as askbrigid.com and myBrigid), CRO No. 762838, Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland Governing law: the laws of Ireland · Supervisory authority: Data Protection Commission (dataprotection.ie)
This Agreement is made under Article 28 of Regulation (EU) 2016/679 (GDPR) and the Data Protection Act 2018 (Ireland). It is concluded in electronic form, which Article 28(9) permits, and takes effect when an authorised representative of the Controller accepts it and the Controller's legal identity is recorded.
1. Parties and roles
Controller: the legal entity named in the acceptance record, being the clinic or practice subscribing to Brigid.
Processor: DJG Media Limited (trading as askbrigid.com and myBrigid), CRO No. 762838, of Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland.
The Controller determines the purposes and means of processing patient personal data. The Processor processes that data only on the Controller's behalf.
2. Subject matter, duration, nature and purpose (Art. 28(3))
Subject matter: provision of the Brigid practice-management platform and its connected services.
Duration: for the term of the subscription, plus any retention period instructed by the Controller or required by law. Each record category follows the retention schedule agreed with the Controller; the working schedule remains a launch gate and this Agreement does not impose one universal period across all clinical and security records.
Nature and purpose: storing, organising, retrieving and transmitting patient and staff records so the Controller can deliver and administer healthcare, including the connected patient and authorised representative access specified in the order. Approved transcription, draft preparation, factual summarisation, patient administration and mailbox processing are included only to the extent recorded in the Controller's feature, purpose and supplier schedules. This Agreement does not itself approve a provider-restricted use or determine a product's regulatory classification.
Types of personal data: identification and contact data; special-category health data including clinical notes, medications, allergies, conditions, results, referrals and prescriptions; billing data; clinician and staff records; and, where included in the agreed scope, consultation audio/transcripts, clinic correspondence and attachments, patient submissions, access/choice evidence and representative-authority records.
Categories of data subjects: the Controller's patients (including children where the clinic treats them), authorised representatives, clinicians, administrative staff and correspondents whose information is processed for the agreed clinic purpose.
3. Processing only on documented instructions (Art. 28(3)(a))
The Processor processes personal data only on the Controller's documented instructions, including as to transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, the Processor informs the Controller before processing, unless that law prohibits it on important grounds of public interest.
The executed order and processing schedules, together with authorised use within that agreed scope, constitute documented instructions. Further instructions may be given in writing. A user action does not expand the agreed purpose, add an unapproved supplier or override a patient choice or applicable law.
The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law.
4. Confidentiality of personnel (Art. 28(3)(b))
The Processor ensures that every person it authorises to process personal data — employee, contractor, or sub-processor personnel — is bound to confidentiality before access is granted, either by a written undertaking in the form published by the Processor or by an appropriate statutory or professional duty of confidence. The Processor maintains a register of the persons so authorised and of the instrument binding each, and makes that register available to the Controller on request.
Access is granted only where necessary for that person's role, is withdrawn when the role changes or ends, and is logged. The confidentiality obligation survives the end of that person's engagement and the end of this Agreement.
5. Security of processing (Art. 28(3)(c), Art. 32)
The Processor implements and maintains appropriate technical and organisational measures, having regard to the state of the art, implementation costs, the nature, scope, context and purposes of processing and the risks to individuals. The measures include encryption in transit and at rest, tenant isolation, individual accounts and role/record access controls, appropriate audit logging, confidentiality, incident handling and tested recovery arrangements.
The attached technical and organisational measures schedule identifies the actual production database and file-backup arrangements, regions, retention, restore procedures and test dates. A database backup is not represented as a backup of separately stored files. The schedule distinguishes implemented and tested controls from planned improvements, and states the evidence for material recovery and deletion commitments.
The Processor regularly tests, assesses and evaluates the effectiveness of the measures and records the method, scope, date and result. It makes relevant information available to the Controller, including material unresolved limitations. Independent testing may supplement internal assessment; a proposed future external assessment does not replace the duty to maintain appropriate security at the start of processing.
6. Sub-processors (Art. 28(2), 28(3)(d), 28(4))
The Controller grants general written authorisation for the Processor to engage sub-processors, subject to this clause.
The Processor publishes a sub-processor inventory covering active, disabled, historical and candidate routes. Appearance in that inventory is not itself evidence that a provider is authorised for a given Controller: the authorised set is the schedule agreed with that Controller.
The Processor gives the Controller at least 30 days' written notice before adding or replacing any sub-processor that processes its data. The Controller may object in writing within that period. Where an objection cannot reasonably be accommodated, the Controller may terminate the subscription without penalty.
The Processor imposes on each sub-processor, by contract, data protection obligations no less protective than those in this Agreement, and remains fully liable to the Controller for the performance of that sub-processor's obligations.
7. Assistance with data subject rights (Art. 28(3)(e))
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data subject rights under Chapter III — access, rectification, erasure, restriction, portability and objection.
Where the Processor receives such a request directly from a data subject, it does not respond substantively but refers the data subject to the Controller and informs the Controller without undue delay. This clause concerns data processed on the Controller's behalf; the Processor handles requests about processing for which it is itself a controller under its own applicable duties.
8. Assistance with Articles 32 to 36 (Art. 28(3)(f))
The Processor assists the Controller in ensuring compliance with the obligations in Articles 32 to 36, taking into account the nature of processing and the information available to it. This includes security of processing, personal data breach notification, communication to data subjects, data protection impact assessments, and prior consultation.
9. Personal data breach (Art. 33(2))
The Processor notifies the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting personal data processed on the Controller's behalf. Notice is given by the Processor's named incident lead or deputy to the contacts the Controller has recorded for this purpose. The Processor maintains a written breach-response procedure that names an incident lead and a deputy, tests the route by which they are reached at least once a year, and records each test.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not available at once, it is provided in phases without further undue delay.
10. Deletion or return of data (Art. 28(3)(g))
At the end of the provision of services, the Controller chooses whether the Processor deletes or returns the personal data processed on its behalf. The Processor acts on that instruction and deletes existing copies, except to the extent that Union or Member State law requires continued storage.
Three periods govern this and are set in the order form executed with each Controller, not fixed here:
- the export window during which the Controller may retrieve its data;
- the active-system deletion deadline after that window closes;
- the backup-expiry process, including when backup copies lapse.
No default period is represented as approved by this published text. Production patient data is not accepted until those three are agreed in writing with the Controller, because a deletion commitment that has not been costed against the actual backup rotation is a promise made in advance of knowing whether it can be kept.
Data returned is provided in a structured, commonly used, machine-readable format. Where law requires retention beyond the agreed periods, the Processor tells the Controller which data is retained, on what legal basis, and for how long.
11. Audit and inspection (Art. 28(3)(h))
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by the Controller or its mandated auditor.
Routine audits are ordinarily arranged on reasonable notice, during business hours and no more than once in twelve months. Those arrangements do not prevent an additional audit or inspection reasonably necessary to verify compliance, including following credible indications of non-compliance, material processing changes, a personal data breach or a competent authority's requirement. Urgency may require shorter notice.
The parties agree proportionate arrangements that protect other customers' information and maintain confidentiality without preventing the Controller from exercising these rights. Reports or certifications may assist an audit but do not replace the Controller's rights under this clause.
12. International transfers (Chapter V)
Personal data is stored at rest within the European Union, except where the Controller has authorised a route in its agreed supplier schedule that identifies a different storage location; that authorisation and the applicable Chapter V safeguards must be in place before the transfer. Publishing an inventory entry or enabling a user-facing option does not by itself establish those safeguards. Where processing by a sub-processor involves a transfer to a third country, the Processor ensures an appropriate transfer mechanism under Chapter V — an adequacy decision, Standard Contractual Clauses, or another lawful mechanism — together with any supplementary measures required, and records the basis for each transfer.
13. Precedence and variation
This Agreement forms part of the subscription between the parties. In the event of conflict between this Agreement and the Terms of Service in respect of the processing of personal data, this Agreement prevails.
The Processor may issue a new version of this Agreement on reasonable notice. Continued use of the service after a new version takes effect does not by itself constitute acceptance of that version where the change materially reduces the Controller's protections; in that case the Processor seeks a fresh acceptance.
14. Execution
Accepted in electronic form under Article 28(9). The acceptance record identifies the Controller's legal entity, its registration number and registered address, the name and role of the authorised signatory, the date and time of acceptance, and the version of this Agreement accepted.
Download the exact document (Markdown)
SHA-256: ce2df8e005e9ad8a40aac0c1466a2eab10ccce72af5134d3a66dc2e4e9d11a72
Source: docs/legal/DPA_2026-09-28_v5.md