ZLysander
Login Sign Up

Contents

  1. Background
  2. Definitions
  3. Roles of the Parties
  4. Processing Instructions
  5. Confidentiality
  6. Security Measures
  7. Sub-processing
  8. Assistance to the Controller
  9. Personal Data Breaches
  10. International Transfers
  11. Audits
  12. Return and Deletion
  13. Liability
  14. Term and Termination
  15. General
  16. Annex A — Details of Processing
  17. Annex B — Security Measures
  18. Annex C — Sub-processors

Data Processing Agreement

Last updated: 18 June 2026  ·  Effective: 18 June 2026

This Data Processing Agreement ("DPA") forms part of, and is governed by, the Terms & Conditions between you (the "Customer") and Haijahr Ltd ("Haijahr", "we", "us") governing your use of Lysander (the "Service"). It records the terms on which Haijahr processes personal data on your behalf, as required by Article 28 of the UK GDPR. Where this DPA conflicts with the Terms in respect of data protection, this DPA prevails.

In plain terms: when you store patient records in Lysander, you decide why and how that data is used — you are the controller. We only act on your instructions to host and process it — we are the processor. This DPA sets out the promises we make as your processor.

1. Background

The Service enables counsellors and coaching practices to manage patient records, session notes, tasks and a patient portal. In doing so, Haijahr processes personal data — including special category data (health information) — on behalf of the Customer. This DPA applies to all such processing for as long as the Customer uses the Service.

2. Definitions

Terms such as controller, processor, data subject, personal data, special category data, processing, personal data breach and supervisory authority have the meanings given to them in UK GDPR and the Data Protection Act 2018 (together, "Data Protection Law").

  • "UK GDPR" means the retained EU law version of the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland.
  • "Sub-processor" means any third party engaged by Haijahr to process personal data under this DPA.
  • "Customer Personal Data" means personal data that Haijahr processes on the Customer's behalf under the Terms, as described in Annex A.

3. Roles of the Parties

The parties agree that, for Customer Personal Data, the Customer is the controller and Haijahr is the processor. The Customer is responsible for establishing a lawful basis for the processing (including, for special category data, a condition under Article 9 UK GDPR) and for meeting its own obligations to data subjects. Haijahr is the controller only for limited account and billing data, which is governed by our Privacy Policy.

4. Processing Instructions

Haijahr shall process Customer Personal Data only on the documented instructions of the Customer, including the instructions set out in this DPA, the Terms, and the Customer's use of the Service's features, unless required to do otherwise by law (in which case Haijahr will inform the Customer of that legal requirement before processing, unless prohibited from doing so).

Haijahr shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.

5. Confidentiality

Haijahr shall ensure that all persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are granted access only on a need-to-know basis. Access to patient data is restricted to personnel who require it to operate, support or maintain the Service.

6. Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing — as well as the risk to data subjects — Haijahr shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. A summary of these measures is set out in Annex B.

7. Sub-processing

The Customer provides general authorisation for Haijahr to engage Sub-processors to process Customer Personal Data, provided that Haijahr:

  • maintains an up-to-date list of Sub-processors at our Sub-processors page;
  • imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA, by written contract;
  • remains fully liable to the Customer for the performance of each Sub-processor's obligations; and
  • gives the Customer prior notice of any intended addition or replacement of a Sub-processor (see Sub-processors), allowing the Customer to object on reasonable data-protection grounds.

If the Customer reasonably objects and the parties cannot resolve the objection, the Customer may terminate the Service in respect of the processing that cannot be performed without the objected-to Sub-processor.

8. Assistance to the Controller

Taking into account the nature of the processing, Haijahr shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to:

  • respond to requests from data subjects exercising their rights under Data Protection Law (such as access, rectification, erasure, restriction, portability and objection);
  • ensure compliance with the Customer's security obligations (Article 32);
  • notify and communicate personal data breaches (Articles 33–34); and
  • carry out data protection impact assessments and prior consultations with the supervisory authority (Articles 35–36).

9. Personal Data Breaches

Haijahr shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it. Haijahr shall cooperate with the Customer and take reasonable steps to mitigate the breach. It remains the Customer's responsibility, as controller, to notify the ICO and affected data subjects where required.

10. International Transfers

Haijahr shall not transfer Customer Personal Data outside the United Kingdom unless it has taken appropriate safeguards in accordance with Data Protection Law — for example, an adequacy decision, the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses. The location of, and transfer mechanism for, each Sub-processor is set out on the Sub-processors page.

11. Audits

Haijahr shall make available to the Customer all information necessary to demonstrate compliance with Article 28 UK GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits will be conducted on reasonable prior notice, no more than once per year (save where required by a supervisory authority or following a breach), during business hours, and subject to confidentiality. Haijahr may satisfy an audit request by providing relevant certifications or third-party audit reports where available.

12. Return and Deletion of Data

On termination of the Service, Haijahr shall — at the Customer's choice — delete or return all Customer Personal Data and delete existing copies, unless storage is required by law. Unless the Customer requests return within 30 days of termination, Haijahr may delete Customer Personal Data after that period. Backups are deleted on the expiry of our standard backup retention cycle.

13. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions.

14. Term and Termination

This DPA takes effect when the Customer first uses the Service and continues for as long as Haijahr processes Customer Personal Data. The obligations in this DPA that by their nature should survive termination — including confidentiality, return/deletion, and liability — shall survive.

15. General

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Terms. If any provision is held invalid, the remainder continues in effect. We may update this DPA to reflect changes in law or our processing; material changes will be notified in line with the Terms.


Annex A — Details of Processing

Subject matterProvision of the Lysander practice-management Service to the Customer.
DurationFor the term of the Customer's use of the Service, plus the return/deletion period in section 12.
Nature and purposeHosting, storage, organisation, retrieval, transmission and deletion of patient records to enable the Customer to manage its counselling practice.
Types of personal dataPatient name, email address, date of birth, phone number; session notes; assigned tasks and uploaded task responses; special category data (health information) contained within notes and tasks; counsellor account details.
Categories of data subjectsThe Customer's patients/clients; the Customer's counsellors and staff users.

Annex B — Technical and Organisational Measures

Haijahr maintains measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and at rest;
  • Access control — role-based access, unique accounts, and least-privilege for support staff;
  • Authentication — hashed credentials and session protection (CSRF tokens);
  • Network and application security — firewalling, patching, and secure development practices;
  • Resilience — regular backups and the ability to restore availability after an incident;
  • Logging and monitoring of access to the production environment;
  • Organisational measures — confidentiality obligations, staff vetting where appropriate, and an incident-response process.

Note for Haijahr: confirm this list reflects your live infrastructure before relying on it.

Annex C — Sub-processors

The current list of authorised Sub-processors, their purposes and locations, is published and kept up to date at https://lysander.app/sub-processors.

Privacy Policy Terms & Conditions Sub-processors
© 2026 Haijahr Ltd. All rights reserved.
Privacy Policy Terms & Conditions Cookie Policy Data Processing Sub-processors Disclaimer Accessibility SLA

🍪 We use cookies

We use essential cookies to keep the site working and optional cookies to improve your experience. By clicking Accept All you consent to all cookies. Privacy Policy · Cookie Policy

Cookie Preferences

Strictly Necessary Always On

Required for the site to function. Includes your session, security token, and login state. These cannot be disabled.

Functional

Remembers your preferences such as "Remember me" on login. Disabling this means you will need to log in each visit.

Analytics & Performance

Helps us understand how visitors use Lysander so we can improve the service. No personal data is shared with third parties.