This Data Processing Agreement ("DPA") forms part of the agreement between Holuvantage Ltd ("Processor") and the subscribing organisation ("Controller") and sets out the terms under which Holuvantage processes personal data on behalf of the Organisation in connection with the Hocare platform. This DPA is required by UK GDPR Article 28.
1. Definitions
In this DPA, terms defined in UK GDPR have the same meaning as in that regulation. In addition:
- "Controller" means the subscribing care organisation
- "Processor" means Holuvantage Ltd, operating the Hocare platform
- "Personal Data" means any information processed by the Processor on behalf of the Controller via Hocare
- "Special Category Data" means health, medication, safeguarding and other sensitive data as defined in UK GDPR Article 9
- "Sub-processor" means any third party engaged by Holuvantage to process Personal Data
2. Roles and responsibilities
The Controller determines the purpose and means of processing Personal Data entered into Hocare. The Controller is responsible for:
- Ensuring a lawful basis exists for all processing carried out through Hocare
- Obtaining necessary consents where required (including from service users and their families)
- Ensuring that individuals whose data is entered into Hocare are informed of that processing
- Responding to data subject rights requests relating to their own data
The Processor (Holuvantage) processes Personal Data only on documented instructions from the Controller, as set out in this DPA and the Terms of Service.
3. Nature and purpose of processing
| Item | Detail |
|---|---|
| Subject matter | Operation of the Hocare care management platform |
| Duration | For the term of the subscription and 90 days following termination |
| Nature of processing | Collection, storage, retrieval, access control, display, transmission, deletion |
| Purpose | To provide GPS visit tracking, eMAR, incident reporting, care records, staff management, AI documentation, and family portal features |
| Data subjects | Care clients, service users, care workers, administrators, family members |
| Categories of data | Identity data, contact data, location data, health data, medication records, incident data, financial data |
| Special category data | Health and medical information, safeguarding records (Article 9 — processed under explicit consent or substantial public interest) |
4. Processor obligations
Holuvantage Ltd agrees to:
- Process Personal Data only on the Controller's documented instructions, except where required by applicable law
- Ensure that persons authorised to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures in accordance with UK GDPR Article 32
- Assist the Controller in responding to data subject rights requests, to the extent technically possible
- Assist the Controller with security obligations, breach notification, data protection impact assessments, and prior consultation with the ICO where required
- Delete or return all Personal Data to the Controller on termination of the subscription, and delete existing copies within 90 days unless retention is required by law
- Make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits conducted by the Controller or its authorised auditor
- Notify the Controller without undue delay of any Personal Data breach affecting data processed under this DPA
5. Technical and organisational security measures
Holuvantage implements the following security measures:
- Encryption — AES-256 encryption at rest; TLS 1.3 in transit
- Access control — Row-level security on all database tables; role-based access throughout the platform
- Authentication — Server-side OTP verification; rate limiting on login attempts; session timeout
- Audit logging — All data access and administrative actions are logged with timestamp and user identity
- Backups — Daily automated backups with point-in-time recovery
- Security testing — Regular security reviews and vulnerability assessments
- Data minimisation — Access to data limited to the minimum necessary for each user role
- Incident response — Documented breach response procedure; ICO notification within 72 hours of becoming aware of a qualifying breach
6. Sub-processors
The Controller provides general authorisation for Holuvantage to engage sub-processors. Holuvantage will notify the Controller of any intended changes to sub-processors with at least 14 days' notice, giving the Controller the opportunity to object.
Current sub-processors are bound by equivalent data protection obligations:
| Function | Data processed | Location |
|---|---|---|
| Cloud database and storage hosting | All platform data at rest | UK / EU |
| Application hosting and delivery | Traffic routing, no long-term storage | UK / EU |
| AI documentation processing | Care note text (not retained after processing) | UK / EU |
| Payment processing | Billing and subscription data only (not care data) | UK / EU |
| Email notification delivery | Recipient address and notification content | UK / EU |
7. International transfers
Holuvantage does not transfer Personal Data outside the UK or European Economic Area. All sub-processors are located within the UK or EU. If this changes, Holuvantage will notify the Controller and implement appropriate transfer safeguards in accordance with UK GDPR Chapter V before any transfer takes place.
8. Data breach notification
In the event of a Personal Data breach affecting data processed under this DPA, Holuvantage will notify the Controller without undue delay and in any event within 48 hours of becoming aware of the breach. Notification will include, to the extent available:
- A description of the nature of the breach, including categories and approximate number of data subjects and records affected
- The contact details of the Holuvantage data protection contact
- The likely consequences of the breach
- Measures taken or proposed to address the breach
The Controller remains responsible for notifying the ICO within 72 hours where required, and for notifying affected data subjects where applicable.
9. Data subject rights
Where the Controller receives a data subject rights request relating to data held in Hocare, Holuvantage will assist by providing relevant data exports, deletion confirmations, or processing restriction flags as technically feasible. Requests should be directed to info@holuvantage.com.
10. Term and termination
This DPA remains in effect for the duration of the subscription and for 90 days following termination. On expiry of the 90-day period, Holuvantage will securely delete all Personal Data processed under this DPA, unless applicable law requires longer retention (for example, financial records required to be held for 6 years under UK tax law).
11. Enterprise DPA
Enterprise subscribers (NHS, local authorities, multi-site organisations) may request a bespoke signed DPA with specific schedules. Contact us at info@holuvantage.com to request this.
Data protection contact
For all data protection queries, DPA requests, or breach notifications:
Holuvantage Ltd · Registered in England & Wales