Your Data Processing Agreement, and what changed in version 1.2
Your clinic is the controller of your patients' data and we are your processor. The Data Processing Agreement is the Article 28 contract that says so, and it sits alongside your subscription agreement. You accepted it when you set your clinic up. The current text is published at aestheticlinic.io/dpa.
Version 1.2, 6 September 2026: nothing for you to accept
Normally a new version asks every clinic owner to accept it before they can carry on working. This one does not. Version 1.2 corrects a description and completes a list; it adds no obligation and changes nothing about how your data is held. Section 6 of the Agreement already covers a change of this kind by giving you notice and a right to object, so it rolls forward and your acceptance carries with it. You get an email telling you, and that is the record.
The version you accepted before this one stays readable on the same page.
What changed
The security description is now accurate
Version 1.0 said your data was encrypted at rest. That was not true, and it was withdrawn in version 1.1 back in August. Version 1.2 states the measures positively instead: everything encrypted in transit, private access-controlled storage, encrypted off-site backups, your integration credentials encrypted, role-based access enforced at the database, tenant isolation between clinics, and audit logging.
Nothing about how your data is held has changed. Only the description of it, which is now true. We would rather tell you that plainly than leave a claim standing that we cannot support.
The sub-processor list is complete
Six services already in use are now named in the annex: Google Maps Places for address autocomplete when you set your clinic address, Google Calendar and Microsoft 365 calendar, Xero, Mailchimp, and Heidi Health. The calendar, accounting, marketing and scribe connectors carry data only if you switch them on, and the last two run on your own account with the provider, which makes that provider your processor rather than ours.
The AI entry now also names the Tidy note clean-up of a treatment-record narrative, which its purpose line had missed. Listing these is a disclosure of what already happens, not a new use of your data.
If you want to object to a sub-processor
You can, on reasonable data-protection grounds. Email hello@aestheticlinic.io. Under section 6 we give you notice by email before a new sub-processor is added, which is why this change arrived that way rather than as a screen you had to click through.
Related
How a patient's erasure request is handled is in Erasing a patient's data, and what is kept. What comes out of the export is in What is inside your data export. Connecting a tool that carries patient data to a third party is section 8 of the Agreement, and the app asks you to confirm your lawful basis at the point you connect it.