Data Processing Agreement
Effective: August 26, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between 1581572 BC Ltd, doing business as Stillpoint (“Stillpoint,” the “processor,” the same contracting entity named in our Business Associate Agreement) and the practice that holds a Stillpoint account (the “practice,” the “controller”). It applies automatically, with no signature required, wherever the practice is established in the United Kingdom, Australia, or New Zealand, or is otherwise subject to the UK GDPR, the Australian Privacy Act 1988, or the New Zealand Privacy Act 2020. For practices in the United States, the Business Associate Agreement accepted in HIPAA mode governs instead of this DPA.
1. What this covers
The practice decides why and how personal data is processed; Stillpoint processes it on the practice’s behalf to provide the service. The processing covers the duration of the practice’s subscription and includes scheduling and booking, client records and clinical documentation, intake forms, invoicing and payments, client communications, and the practice’s published website.
Categories of data.Client contact details, appointment and booking history, payment records, communications, and, where the practice uses clinical features, health information the practice or its clients enter. Data subjects are the practice’s clients, staff, and practitioners.
2. Stillpoint’s commitments
- Process personal data only on the practice’s documented instructions, which are given by using the service and its settings, unless required otherwise by law, in which case Stillpoint will inform the practice unless the law prevents it.
- Ensure every person authorised to process the data is bound by confidentiality.
- Apply appropriate technical and organisational security measures, including encryption in transit and at rest, practice-level data separation enforced through database row-level security for operational data and a dedicated, audited data-access layer for health information, role-based access controls, multi-factor authentication available for every staff account, and audit logging of access to health information. These are the same controls maintained for Stillpoint’s HIPAA compliance program and described in the privacy policy.
- Assist the practice, taking into account the nature of the processing, in responding to data subject requests (access, correction, deletion, portability) and in meeting its security, breach notification, and impact assessment obligations.
- Notify the practice without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting the practice’s data, with the information the practice needs to meet its own notification obligations.
- At the end of the subscription, delete or return the practice’s personal data at the practice’s choice, subject to legal retention requirements. The practice can export its data, including client records and clinical notes, at any time from its settings.
- Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by written request to the contact below.
3. Sub-processors
The practice gives Stillpoint general authorisation to engage the sub-processors listed at withstillpoint.com/subprocessors. Stillpoint imposes data protection obligations on each sub-processor equivalent to those in this DPA and remains responsible for their performance. Material changes to the list are posted on that page and emailed to practice owners at least 14 days before the change takes effect; a practice that objects may terminate its subscription before the change applies.
4. International transfers
Stillpoint stores and processes data on Amazon Web Services in the United States (us-east-1, N. Virginia), as disclosed in the privacy policy.
United Kingdom.Transfers of UK personal data are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (issued under s119A of the Data Protection Act 2018), which is incorporated into this DPA by reference and completed as follows. Table 1: the practice is the data exporter and 1581572 BC Ltd, doing business as Stillpoint, is the data importer, each with the contact details held on the practice’s account and the contact in section 6. Table 2: the Addendum EU SCCs are Module Two (controller to processor), with the optional docking clause not used, general authorisation for sub-processing under clause 9(a) with the 14 day notice period in section 3, the optional redress clause not used, and the governing law and forum of clauses 17 and 18 being England and Wales. Table 3: Annex 1A and 1B are the parties and processing details in section 1, and Annex II is the security measures in section 2. Table 4: either party may end the Addendum as set out in section 19 of the Addendum. The mandatory clauses of Part 2 of the Addendum apply as written. In case of conflict between the Addendum and this DPA, the Addendum prevails.
Australia and New Zealand.This DPA constitutes the contractual safeguard through which the practice meets Australian Privacy Principle 8.1 and New Zealand Information Privacy Principle 12: Stillpoint undertakes to handle the practice’s personal data in a manner consistent with the Australian Privacy Principles and the New Zealand privacy principles respectively, and this undertaking is enforceable by the practice.
5. General
This DPA is governed by the same law and forum as the practice’s main agreement with Stillpoint, and liability under it is subject to the limitations in that agreement. If any provision of this DPA conflicts with the terms of service, this DPA prevails with respect to the processing of personal data.
6. Contact
Questions about this DPA, data subject requests, audits, and objections to sub-processor changes all reach us at help@withstillpoint.com.
1581572 BC Ltd, doing business as Stillpoint
PO Box 5121, Victoria PO 9, BC V8R 6N4, Canada
help@withstillpoint.com