Data Processing Agreement

Between you (the Customer, acting as Data Controller) and Ankorium (acting as Data Processor) under UK GDPR and the Data Protection Act 2018.

Version 1.0 · Effective from the date the Customer signs up to the Ankorium platform · Last revised: 8 May 2026

Get a signed copy

Print this page (Ctrl/Cmd + P) for a clean PDF, or email [email protected] for a Word version.

Print or save PDF
Before you sign

This is a real Data Processing Agreement, not a placeholder. Even so, we strongly recommend you have your own solicitor review it before signing - particularly if you process special category data (health, biometric, religious belief) or if you are a regulated professional under CNHC, BANT, NTC, IPHM, or similar. Ankorium is operated by a sole trader, not a law firm.

1. Introduction and parties

1.1 This Data Processing Agreement (the "DPA") forms part of the agreement between:

  • The Customer - the person or organisation that has signed up to use the Ankorium platform (referred to as "you" or "the Controller"); and
  • Ankorium - operated by Ian Crocker, a sole trader based in Cornwall, United Kingdom, with contact email [email protected] (referred to as "we", "us", or "the Processor").

1.2 This DPA governs our processing of personal data on your behalf in connection with the Ankorium platform service (the "Service") and applies in addition to our Terms of Service and Privacy Policy.

1.3 If there is any conflict between this DPA and the Terms of Service in respect of personal data processing, this DPA prevails.

2. Definitions

2.1 Terms used in this DPA have the meanings given to them in the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018"). In particular:

  • "Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Sub-processor" have the meanings given in UK GDPR.
  • "Customer Personal Data" means Personal Data that we Process on your behalf as part of providing the Service.
  • "Data Subject" in this DPA primarily refers to the natural persons whose data you (the Controller) collect and which we Process on your behalf - typically your clients, members, students, course participants, and event attendees.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

3. Roles and responsibilities

3.1 You are the Controller of Customer Personal Data. We are the Processor. You determine the purposes and means of Processing; we Process Customer Personal Data only on your documented instructions.

3.2 You confirm that:

  • You have a valid lawful basis (under Article 6 UK GDPR) and, where relevant, an additional condition (under Article 9) for the Processing you instruct us to carry out.
  • You have provided all required notices to Data Subjects, including in respect of our role as Processor.
  • You will not provide us with instructions that would cause us to breach any applicable data protection law.

3.3 Your documented instructions are: (a) this DPA; (b) the configuration of your Ankorium tenant; (c) any specific instructions you give us in writing (including by email).

4. Subject matter, duration, nature, and purpose of Processing

4.1 The full details of the Processing are set out in Annex I. In summary:

  • Subject matter: the provision of the Ankorium platform service to you.
  • Duration: the term of your subscription, plus a 30-day grace period for data export, plus retention periods for data we are legally required to keep (e.g. financial records).
  • Nature: hosting, storing, transmitting, displaying, backing up, and otherwise handling Customer Personal Data as required to deliver the Service.
  • Purpose: to provide the Service in accordance with our agreement with you.

5. Our obligations as Processor

5.1 We will:

  1. Process Customer Personal Data only on your documented instructions, including with regard to international transfers, except where required by law (in which case we will inform you of that legal requirement before Processing, unless the law prohibits doing so);
  2. Ensure that all personnel authorised to Process Customer Personal Data are bound by appropriate confidentiality obligations;
  3. Implement and maintain the technical and organisational security measures set out in Annex II;
  4. Engage Sub-processors only in accordance with Section 7 of this DPA;
  5. Assist you, taking into account the nature of the Processing, to fulfil your obligations to respond to Data Subject rights requests, as set out in Section 8;
  6. Assist you, taking into account the nature of the Processing and the information available to us, in your obligations under Articles 32 to 36 of UK GDPR (security, breach notification, Data Protection Impact Assessments, and prior consultation);
  7. At your choice, return or delete all Customer Personal Data after the end of the provision of the Service, as set out in Section 12;
  8. Make available to you all information necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits as set out in Section 11.

6. Confidentiality

6.1 We will treat Customer Personal Data as confidential. Personnel with access to Customer Personal Data are subject to written confidentiality obligations.

6.2 We will not access Customer Personal Data except as strictly necessary to: (a) operate, maintain, troubleshoot, and back up the Service; (b) respond to your support requests; (c) prevent or address technical or security issues; or (d) comply with a legal obligation.

7. Sub-processors

7.1 You give us general written authorisation to engage Sub-processors to Process Customer Personal Data on our behalf, subject to this Section 7.

7.2 The current list of Sub-processors is published at ankorium.com/trust and forms part of this DPA as Annex III.

7.3 We will: (a) impose data protection terms on each Sub-processor that are no less protective than those in this DPA; and (b) remain liable to you for the acts and omissions of each Sub-processor as if they were our own.

7.4 Where we propose to engage a new Sub-processor, or replace an existing one with one that materially changes the Processing, we will give you at least 14 days' prior notice by email. You may object to the change for reasonable data protection grounds. If we cannot accommodate your objection, you may terminate your subscription on written notice with no penalty and we will refund any pre-paid fees pro-rata.

8. Data subject rights

8.1 The Service includes self-service tools that enable you to fulfil Data Subject rights requests yourself: access, rectification, erasure, restriction, and portability. These are documented at ankorium.com/trust.

8.2 If you receive a Data Subject rights request that you cannot fulfil through the Service, contact us at [email protected]. We will assist you to respond within the timescales required by UK GDPR (one month, extendable in limited circumstances).

8.3 If we receive a Data Subject rights request directly from a Data Subject relating to Customer Personal Data, we will: (a) not respond directly except to acknowledge receipt; (b) inform the Data Subject that they should contact you; and (c) notify you of the request without undue delay.

9. Personal Data Breaches

9.1 We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 hours of our awareness of the breach.

9.2 Our notification will include, to the extent known at the time:

  • The nature of the breach, the categories and approximate number of Data Subjects affected, and the categories and approximate number of Personal Data records affected;
  • The likely consequences of the breach;
  • Measures taken or proposed to address the breach and to mitigate its possible adverse effects;
  • The contact point at Ankorium for further information.

9.3 We will continue to provide updates as more information becomes available, and will support your assessment of whether the breach is notifiable to the ICO under Article 33 UK GDPR or to Data Subjects under Article 34.

9.4 The fact that we notify you of an incident does not in itself constitute an admission of fault or liability.

10. Data Protection Impact Assessments

10.1 We will provide reasonable assistance to you in connection with any Data Protection Impact Assessment ("DPIA") you carry out in respect of Processing involving Customer Personal Data. This may include providing information about the security measures, sub-processors, and data flows involved in the Service.

10.2 A DPIA template covering the typical Ankorium use case is available on request from [email protected].

11. Audits

11.1 On your reasonable written request (no more than once in any 12-month period unless required by a regulator), we will provide:

  • Written responses (on a confidential basis) to reasonable audit-related enquiries you raise;
  • Confirmation of our security measures and compliance with this DPA;
  • Copies of relevant third-party security assessments or certifications, if and when held.

11.2 Where the information provided under clause 11.1 is not sufficient to satisfy your audit obligations, you may carry out (or appoint a qualified third party to carry out) an audit of our processes and facilities, on at least 30 days' written notice, during normal business hours, and in a manner that does not unreasonably disrupt the Service. The auditor must agree to confidentiality terms acceptable to us.

11.3 Each party bears its own costs of any audit, except that we may charge our reasonable costs of supporting an audit if it is conducted otherwise than in connection with a regulator's specific request.

12. Return and deletion of data

12.1 Within 30 days of the end of your subscription, you may export Customer Personal Data using the Service's export functions. We will provide reasonable assistance with the export on request.

12.2 After the 30-day grace period, we will delete or anonymise Customer Personal Data within 60 days, except for: (a) data we are legally required to retain (for example, financial records retained for 7 years under HMRC requirements); and (b) data held in encrypted backups, which is overwritten on the standard backup rotation cycle (within 30 days).

12.3 On written request, we will provide a written confirmation of deletion.

13. International transfers

13.1 Customer Personal Data is hosted on a server physically located in the United Kingdom.

13.2 Where Sub-processors are located outside the UK or EEA, we ensure that an adequate transfer mechanism is in place, such as the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant). The transfer mechanism applicable to each Sub-processor is identified in Annex III.

14. Liability

14.1 The liability provisions of our Terms of Service apply to any claim under this DPA, except that we will not exclude or limit liability where it cannot be excluded or limited by law (including for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation).

14.2 Each party will be liable for the consequences of its own breaches of UK GDPR and this DPA. The fact that we Process on your instructions does not relieve you of your obligations as Controller.

15. Term and termination

15.1 This DPA takes effect on the date you sign up to the Service and continues until: (a) you stop using the Service and we have completed the data return / deletion process under Section 12; or (b) it is replaced by a written agreement signed by both parties.

15.2 Termination of the underlying subscription does not affect any rights or obligations that by their nature continue (for example, confidentiality, deletion obligations, and any cause of action arising before termination).

16. Governing law

16.1 This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales, except that you may bring claims arising from a Personal Data Breach in any court of competent jurisdiction in your habitual residence.

17. General

17.1 If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force.

17.2 We may update this DPA where required by changes in law, sub-processor arrangements, or to reflect material changes in the Service. Material updates will be notified to you by email at least 30 days in advance, except where a shorter period is required by law. Your continued use of the Service after the effective date of an update constitutes acceptance.

17.3 A person who is not a party to this DPA has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.

Annex I - Description of Processing

Subject matterProvision of the Ankorium platform: a multi-feature SaaS for practitioners (website, blog, community, courses, events, calendar, email marketing, digital products, video, AI assistance, and clinical journaling, depending on the modules enabled on the Customer's subscription tier).
DurationThe term of the Customer's subscription, plus a 30-day grace period for data export, plus statutory retention periods for data we are required by law to keep (e.g. 7 years for financial records).
Nature of ProcessingCollection, storage, organisation, retrieval, use, transmission, disclosure (only to the Sub-processors listed in Annex III), erasure, and destruction.
Purpose of ProcessingTo provide the Service to the Customer in accordance with the Terms of Service and the Customer's instructions.
Categories of Data Subjects(a) Customer's clients, members, students, course participants, event attendees, mailing list subscribers; (b) Customer's staff and associates; (c) the Customer themselves.
Categories of Personal DataIdentification data (name, email, phone), profile data (bio, avatar, preferences), engagement data (posts, comments, reactions, course progress, event attendance), transactional data (bookings, purchases, payment metadata - payment instruments are held by Stripe), communication data (messages, emails, support enquiries), and (where the Customer enables clinical journaling) consultation notes and treatment plan content. The Customer is responsible for the legal basis for collecting any special category data.
Special category dataWhere the Customer collects health, biometric, or other special category data through the Service (for example, in clinical notes or intake forms), the Customer must ensure they have an appropriate condition under Article 9 UK GDPR. Ankorium provides infrastructure for storing such data securely but does not determine the lawful basis.

Annex II - Technical and organisational measures

The following measures are implemented and maintained by Ankorium pursuant to Article 32 UK GDPR. These measures are reviewed regularly and updated to reflect the state of the art and the risks presented by the Processing.

Encryption

  • All connections to the Service use TLS 1.3 (or the latest practical secure version).
  • Clinical and personal free-text fields — including consultation notes, session transcripts and AI-generated session summaries — are encrypted at the application layer (AES-256-GCM) before being written to the database, under a key set held separately from the credentials key set. A database dump therefore shows ciphertext for those fields.
  • Uploaded files (session audio, voice and photo captures, diary photographs) are stored outside any publicly served directory and are retrievable only through authenticated, role-checked, tenant-scoped routes. They are not themselves encrypted at rest; the underlying server disk volume is not encrypted.
  • Backups are encrypted at rest.

Access control

  • Customer access is via email + password with JWT-secured sessions.
  • Admin access (Ankorium personnel) uses a separate authentication path with logged access.
  • No master password or back-door account exists.
  • Personnel access to Customer Personal Data is restricted to operational necessity and is logged.

Tenant isolation

  • Every database query is scoped to a single tenant by middleware enforcement.
  • Cross-tenant data leakage is prevented architecturally and tested.

Application security

  • All user-submitted input is sanitised against script injection and malicious event handlers.
  • All database queries are parameterised; no string-concatenated SQL.
  • Rate limiting: 300 read requests / 60 write requests / 15 authentication attempts per 15 minutes per origin.
  • HTTP security headers (CSP, X-Frame-Options, HSTS, etc.) are applied.
  • Output sanitisation (DOMPurify or equivalent) on all rich text rendering.

Backups and disaster recovery

  • Database backups run nightly, encrypted, retained for 30 days, with monthly restore testing.
  • Backups are held encrypted on a separate offsite server operated by a second hosting provider, so that loss of the primary server does not take the backups with it.

Payment data

  • Card numbers, CVCs, and bank details are processed exclusively by Stripe (PCI-DSS Level 1).
  • Ankorium retains only Stripe reference identifiers, never payment instrument data.

Incident response

  • An internal incident response procedure is maintained, prioritising containment, evidence preservation, customer notification, and accurate communication.
  • Customer notification of a Personal Data Breach is within 24 hours of awareness.

Personnel

  • All personnel with access to Customer Personal Data are subject to written confidentiality obligations.
  • Personnel are trained on UK GDPR and Ankorium data handling policy.

Annex III - List of Sub-processors

The current list of Sub-processors is maintained at ankorium.com/trust and is updated whenever a Sub-processor is added, replaced, or materially changes role. The version current at the date of this DPA is reproduced below; the up-to-date version on the Trust page prevails.

Sub-processorPurposeLocationTransfer safeguard
StripeCard payment processing for Customers who connect their own Stripe account; the Customer is the merchant of record and funds settle directly to them.UK / IE / USUK adequacy + SCCs
Postmark (ActiveCampaign Inc.)Transactional and campaign email delivery.USSCCs + DPA
AnthropicClaude AI for content generation, course building, AI assistant.USSCCs + Anthropic DPA, no-training opt-out
Bunny.netVideo hosting and CDN delivery.EU (Slovenia)Within UK adequacy / EEA
ZoomOptional video meeting integration; only active for Customers who connect Zoom.USSCCs + Zoom DPA
SpeechmaticsReal-time speech-to-text for the live session scribe; receives session audio while a session is being transcribed. Only active for Customers who enable live transcription, and only where the client has given recording consent.EUWithin UK adequacy / EEA
Google (Calendar API)Optional calendar sync; appointment details including client name, email and phone are written into the Customer's own Google Calendar. Only active for Customers who connect Google Calendar.USSCCs + Google DPA
EventbriteOptional event-ticketing integration; attendee name and email are exchanged. Only active for Customers who connect Eventbrite.USSCCs + Eventbrite DPA
PitchupOptional pitch/site booking sync for hospitality Customers; guest name, email and phone are exchanged. Only active for Customers who connect Pitchup.UKWithin UK adequacy
VPS infrastructure providerPhysical server hosting the Ankorium application and database.UKWithin UK adequacy
Offsite backup providerSecond hosting provider holding the encrypted offsite backup of the primary server.UKWithin UK adequacy

Self-hosted on Ankorium infrastructure (not third-party Sub-processors): LiveKit (video conferencing), Qdrant (vector search), Ollama (local AI embeddings).

Signatures

By signing up to the Ankorium platform, the Customer accepts this DPA in its current version. For Customers who require a counter-signed copy, this page may be printed and signed; we will counter-sign on request.

The Customer (Controller)

Signed
Name & role
Organisation
Date

Ankorium (Processor)

Signed
Ian Crocker, Ankorium
Date

Document version 1.0 · Last revised 8 May 2026 · Questions: [email protected]