Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of, and is governed by, the Terms & Conditions between you (the "Customer") and Haijahr Ltd ("Haijahr", "we", "us") governing your use of Lysander (the "Service"). It records the terms on which Haijahr processes personal data on your behalf, as required by Article 28 of the UK GDPR. Where this DPA conflicts with the Terms in respect of data protection, this DPA prevails.
1. Background
The Service enables counsellors and coaching practices to manage patient records, session notes, tasks and a patient portal. In doing so, Haijahr processes personal data — including special category data (health information) — on behalf of the Customer. This DPA applies to all such processing for as long as the Customer uses the Service.
2. Definitions
Terms such as controller, processor, data subject, personal data, special category data, processing, personal data breach and supervisory authority have the meanings given to them in UK GDPR and the Data Protection Act 2018 (together, "Data Protection Law").
- "UK GDPR" means the retained EU law version of the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland.
- "Sub-processor" means any third party engaged by Haijahr to process personal data under this DPA.
- "Customer Personal Data" means personal data that Haijahr processes on the Customer's behalf under the Terms, as described in Annex A.
3. Roles of the Parties
The parties agree that, for Customer Personal Data, the Customer is the controller and Haijahr is the processor. The Customer is responsible for establishing a lawful basis for the processing (including, for special category data, a condition under Article 9 UK GDPR) and for meeting its own obligations to data subjects. Haijahr is the controller only for limited account and billing data, which is governed by our Privacy Policy.
4. Processing Instructions
Haijahr shall process Customer Personal Data only on the documented instructions of the Customer, including the instructions set out in this DPA, the Terms, and the Customer's use of the Service's features, unless required to do otherwise by law (in which case Haijahr will inform the Customer of that legal requirement before processing, unless prohibited from doing so).
Haijahr shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
5. Confidentiality
Haijahr shall ensure that all persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are granted access only on a need-to-know basis. Access to patient data is restricted to personnel who require it to operate, support or maintain the Service.
6. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing — as well as the risk to data subjects — Haijahr shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. A summary of these measures is set out in Annex B.
7. Sub-processing
The Customer provides general authorisation for Haijahr to engage Sub-processors to process Customer Personal Data, provided that Haijahr:
- maintains an up-to-date list of Sub-processors at our Sub-processors page;
- imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA, by written contract;
- remains fully liable to the Customer for the performance of each Sub-processor's obligations; and
- gives the Customer prior notice of any intended addition or replacement of a Sub-processor (see Sub-processors), allowing the Customer to object on reasonable data-protection grounds.
If the Customer reasonably objects and the parties cannot resolve the objection, the Customer may terminate the Service in respect of the processing that cannot be performed without the objected-to Sub-processor.
8. Assistance to the Controller
Taking into account the nature of the processing, Haijahr shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to:
- respond to requests from data subjects exercising their rights under Data Protection Law (such as access, rectification, erasure, restriction, portability and objection);
- ensure compliance with the Customer's security obligations (Article 32);
- notify and communicate personal data breaches (Articles 33–34); and
- carry out data protection impact assessments and prior consultations with the supervisory authority (Articles 35–36).
9. Personal Data Breaches
Haijahr shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it. Haijahr shall cooperate with the Customer and take reasonable steps to mitigate the breach. It remains the Customer's responsibility, as controller, to notify the ICO and affected data subjects where required.
10. International Transfers
Haijahr shall not transfer Customer Personal Data outside the United Kingdom unless it has taken appropriate safeguards in accordance with Data Protection Law — for example, an adequacy decision, the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses. The location of, and transfer mechanism for, each Sub-processor is set out on the Sub-processors page.
11. Audits
Haijahr shall make available to the Customer all information necessary to demonstrate compliance with Article 28 UK GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits will be conducted on reasonable prior notice, no more than once per year (save where required by a supervisory authority or following a breach), during business hours, and subject to confidentiality. Haijahr may satisfy an audit request by providing relevant certifications or third-party audit reports where available.
12. Return and Deletion of Data
On termination of the Service, Haijahr shall — at the Customer's choice — delete or return all Customer Personal Data and delete existing copies, unless storage is required by law. Unless the Customer requests return within 30 days of termination, Haijahr may delete Customer Personal Data after that period. Backups are deleted on the expiry of our standard backup retention cycle.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions.
14. Term and Termination
This DPA takes effect when the Customer first uses the Service and continues for as long as Haijahr processes Customer Personal Data. The obligations in this DPA that by their nature should survive termination — including confidentiality, return/deletion, and liability — shall survive.
15. General
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Terms. If any provision is held invalid, the remainder continues in effect. We may update this DPA to reflect changes in law or our processing; material changes will be notified in line with the Terms.
Annex A — Details of Processing
| Subject matter | Provision of the Lysander practice-management Service to the Customer. |
|---|---|
| Duration | For the term of the Customer's use of the Service, plus the return/deletion period in section 12. |
| Nature and purpose | Hosting, storage, organisation, retrieval, transmission and deletion of patient records to enable the Customer to manage its counselling practice. |
| Types of personal data | Patient name, email address, date of birth, phone number; session notes; assigned tasks and uploaded task responses; special category data (health information) contained within notes and tasks; counsellor account details. |
| Categories of data subjects | The Customer's patients/clients; the Customer's counsellors and staff users. |
Annex B — Technical and Organisational Measures
Haijahr maintains measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest;
- Access control — role-based access, unique accounts, and least-privilege for support staff;
- Authentication — hashed credentials and session protection (CSRF tokens);
- Network and application security — firewalling, patching, and secure development practices;
- Resilience — regular backups and the ability to restore availability after an incident;
- Logging and monitoring of access to the production environment;
- Organisational measures — confidentiality obligations, staff vetting where appropriate, and an incident-response process.
Note for Haijahr: confirm this list reflects your live infrastructure before relying on it.
Annex C — Sub-processors
The current list of authorised Sub-processors, their purposes and locations, is published and kept up to date at https://lysander.app/sub-processors.