Data Processing Agreement
Last updated: June 2026
This DPA supplements and forms part of the Terms of Service between you (the "Controller" or "Covered Entity") and Toctive Ltd. (the "Processor" or "Business Associate"). By using the MediSync Service, you agree to the terms of this DPA. If you require a countersigned copy of this DPA, please contact [email protected].
Roles and responsibilities
You, the healthcare organisation or clinic, act as the Data Controller (under GDPR) or Covered Entity (under HIPAA) in respect of all personal data and protected health information (PHI) relating to your clients and staff that you upload to, or generate through, the MediSync platform. Toctive Ltd. acts as the Data Processor (under GDPR) or Business Associate (under HIPAA) and processes that data solely on your documented instructions. MediSync does not determine the purposes or means of processing your clinical data — that responsibility remains with you.
Categories of personal data processed
In the course of providing the Service, MediSync may process the following categories of personal data on your behalf: (a) Client data — names, dates of birth, contact details, national identification numbers, appointment history, medical notes, prescriptions, diagnoses, and any other health-related information you enter into the platform; (b) Staff data — names, email addresses, job titles, shift records, role assignments, and login credentials for members of your organisation; (c) Billing contact data — names and email addresses of billing contacts at your organisation. Special category data under GDPR (health data, Article 9) is processed under Article 9(2)(h) (healthcare provision purposes) as directed by you.
Purposes and legal basis for processing
MediSync processes personal data solely to provide, maintain, and support the Service in accordance with your instructions and our Terms of Service. We do not use your clients’ data for profiling, advertising, or any purpose other than operating the Service for your benefit. The legal bases for processing under GDPR depend on the nature of the data and your jurisdiction; as the Controller, you are responsible for ensuring you have an appropriate legal basis (e.g. legitimate interests, contractual necessity, or explicit consent) for uploading and processing client data within the platform.
Sub-processors
We engage carefully vetted sub-processors to provide infrastructure, databases, email delivery, monitoring, and support services that underpin the MediSync platform. All sub-processors are bound by data processing agreements that impose data protection obligations at least as stringent as those in this DPA. We maintain a current list of sub-processors, which is available upon request at [email protected]. We will give you at least 30 days’ advance notice before engaging a new sub-processor, and you may object to any new sub-processor within that period. If we cannot accommodate your objection, you may terminate the Service without penalty.
Security measures
Toctive Ltd. implements and maintains appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include: AES-256 encryption at rest and TLS 1.2+ in transit; strict role-based and least-privilege access controls; multi-factor authentication for all staff with access to production data; per-tenant row-level security at the database layer; continuous security monitoring and intrusion detection; annual penetration testing by independent third parties; a formal vulnerability management programme; and business continuity and disaster recovery plans tested at least annually. Full details are available in our Security documentation.
Data subject rights
As the Data Controller, you are responsible for responding to data subject requests from your clients and staff (e.g. requests to access, correct, delete, or port their personal data). MediSync will assist you in fulfilling these obligations by providing the technical means to export and delete data within the platform. If MediSync receives a data subject request directly relating to data you control, we will promptly forward it to you. We will not respond to data subject requests on your behalf without your authorisation, except where required by law. We will respond to your reasonable requests for assistance within 5 business days.
Data breach notification
In the event of a personal data breach (as defined under applicable law) affecting data we process on your behalf, MediSync will: (a) notify you without undue delay, and in any event within 72 hours of becoming aware of the breach; (b) provide you with sufficient information to enable you to assess the likely consequences of the breach and fulfil your own notification obligations to supervisory authorities and affected data subjects; (c) cooperate fully with your investigation and remediation efforts; (d) take all reasonable steps to mitigate the effects of the breach and prevent recurrence. The notification will include, where available, a description of the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed to address the breach.
Term, termination, and data return
This DPA remains in force for the duration of the Services Agreement. Upon termination or expiry of the Services Agreement for any reason, MediSync will, at your choice, either return all personal data to you in a machine-readable format or securely delete it from our systems within 90 days of termination, unless longer retention is required by applicable law. We will provide you with a written certification of deletion upon request. During the 90-day period following termination, you may export your data through the account settings. After this window, permanent deletion is irreversible. Any sub-processors engaged by MediSync are required to comply with equivalent deletion obligations.