Legal

Data Processing Agreement

This sets out how Holder processes the personal data of your clients on your behalf. It forms part of, and is subject to, our Terms of Service, takes effect automatically when you create your account — no signature is needed — and continues for as long as Holder processes your clients' personal data. If you need a countersigned copy for your own records or compliance, ask us at info@holder.cloud and we will provide one.

Last updated 24 July 2026

Roles and scope

For your clients’ personal data, you are the controller and Holder is the processor. You decide what is collected and why; Holder processes it only to provide the service to you. This agreement applies to Holder’s processing of that personal data under the Terms of Service. The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in the Annex below.

Instructions

Holder processes your clients’ personal data only on your documented instructions — which include the instructions given through your configuration and use of the product’s features, and any further written instructions you give us — and as needed to provide and secure the service, or where required by law. If we believe an instruction breaches data-protection law, we will tell you. If we are required by law to process the data otherwise than on your instructions, we will tell you first, unless the law prevents us.

Special-category data. Client records you store may include health or other special-category data. As controller, you are responsible for ensuring a lawful basis and a valid Article 9 condition — typically your clients’ explicit consent — before storing it. We process such data only as part of the service, on your documented instructions, and the service records each consent change in an append-only log to help you demonstrate this.

Interface translations. Where you have not turned off translation sharing under the Terms of Service, Holder acts as an independent controller for the limited, automated processing needed to identify and screen translations of Holder’s standard text and make them available as default wording for other customers. This processing is designed to exclude personal data, and never involves your clients’ personal data.

Confidentiality

No one at Holder accesses your clients’ data without your written permission, except where strictly necessary to provide support you have requested, or to comply with the law. Personnel authorised to process the data are bound by appropriate, enforceable confidentiality obligations.

Security measures

Taking account of the state of the art, the costs of implementation, and the nature of the processing, Holder maintains appropriate technical and organisational measures under Article 32 UK GDPR, including:

  • encryption of personal data in transit and at rest;
  • strict tenant isolation — each practice’s data is sealed from every other, enforced with row-level security at the database itself;
  • access controls and the principle of least privilege;
  • measures to maintain the ongoing confidentiality, integrity, availability and resilience of the service, including backups and the ability to restore;
  • regular testing and review of the effectiveness of these measures.

A fuller summary of our security measures is available on request.

Sub-processors

You give Holder general authorisation to engage the sub-processors listed below to deliver the service. Holder remains responsible for their performance under this agreement.

  • Supabase — hosting and database (EU, Ireland);
  • Vercel — application hosting (EU, Ireland);
  • Stripe — payments (your client payments run through your own Stripe account);
  • Amazon Web Services — email delivery (Amazon SES) and SMS messaging (EU, Ireland);
  • Anthropic — AI features, contracting through its EU entity in Ireland under a Data Processing Addendum that incorporates the EU SCCs and the UK IDTA. Anthropic does not use the data to train models and deletes inputs and outputs within 30 days. For the contact-research feature, Anthropic engages a third-party web search provider as a further sub-processor, operating under its own terms.
  • Cloudflare (Turnstile) — bot protection on public pages;
  • 8x8 (Jitsi as a Service) — video for online sessions.

We give you at least 30 days’ advance notice before adding or replacing any sub-processor, during which you may object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected part of the service.

Assisting you

Taking account of the nature of the processing and the information available to us, Holder assists you by appropriate technical and organisational measures, so far as possible, in meeting your own obligations — including responding to your clients’ data-subject requests, keeping the data secure, notifying personal-data breaches, carrying out data-protection impact assessments, and consulting the supervisory authority where required. Holder provides the tools and reasonable assistance for you, as controller, to respond to data-subject requests within the time the law allows. Where one of your clients exercises a data-subject right with us directly, we will, unless the law requires otherwise, refer them to you, since you are the controller.

Personal-data breaches

If Holder becomes aware of a breach affecting your clients’ personal data, we notify you without undue delay, and in any event within 48 hours of becoming aware of it. Our notification will describe, so far as we can, the nature of the breach, its likely consequences, the measures taken or proposed, and a point of contact — so that you can meet your own obligations.

International transfers

Your clients’ data is hosted in the EU (Ireland). Where any sub-processor processes personal data outside the UK and EEA, the transfer is made under an approved transfer mechanism — the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, or an applicable adequacy decision — and Holder will provide details of the mechanism that applies on request.

Return and deletion

You can export your clients’ data at any time during the term. On termination, you may ask us to return the data, and we delete it from our active systems within 30 days, and from routine backups within a further 90 days, except where we are required by law to keep it for longer. If you ask for return, we provide the data in a commonly used, machine-readable format before deletion. Where your account is suspended and not restored, we may delete your clients’ data 6 months after suspension on the same terms as deletion on termination, provided we have emailed you at least 14 days beforehand; that notice is your opportunity to ask for return of the data first.

Where you use the contact-research feature: when you delete a contact, we delete the associated research brief from our active systems without undue delay, and purge it from backups on the ordinary backup-expiry cycle, during which those backups are held beyond use. We assist you in responding to requests from researched individuals, including objections (Article 21), rectification and erasure.

Audit

Holder makes available the information reasonably needed to demonstrate compliance with this agreement, including a security summary and relevant third-party reports where available. Holder also allows for and contributes to audits, including inspections, conducted by you or an auditor you appoint — no more than once a year, and following a personal-data breach — on reasonable prior notice, during business hours, subject to confidentiality, and without compromising the security or data of other customers.

Liability

The liability of each party under this agreement is subject to the limitations and exclusions of liability set out in the Terms of Service, which apply to this agreement as if set out here. Nothing in this agreement limits liability that cannot be limited by law.

General

This agreement is part of, and subject to, the Terms of Service; if there is a conflict on matters of data protection, this agreement takes precedence. It is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. It takes effect when you accept the Terms of Service by creating your account; a countersigned copy is available on request.

Annex — details of the processing

  • Subject-matter: provision of the Holder practice-management service.
  • Duration: for the term of your subscription, and until the data is returned or deleted under "Return and deletion" above.
  • Nature and purpose: hosting, storage, organisation and processing of client records to provide the service’s features — records, notes, bookings, messaging, payments via your connected Stripe account, and, where enabled, AI-assisted features.
  • Types of personal data: contact details, booking and session records, notes and messages you choose to store, and any other data you enter.
  • Categories of data subjects: your clients, and other individuals whose data you choose to store.
  • Special-category data: only where you choose to store it; you are responsible for ensuring a lawful basis and any additional conditions apply.

Contact research (where enabled). Nature and purpose: searching publicly available sources and generating a written research brief about a customer contact, to support professional outreach, on your documented instruction (initiated when you use the feature). Data subjects: your professional contacts (third parties). Personal data: names and professional identifiers, publicly available professional information, and the AI-generated brief. Duration: until the contact is deleted or 12 months, whichever is sooner.

A countersigned copy

This agreement is accepted electronically at sign-up and is binding from that point — most customers never need anything further. If your own compliance process requires a countersigned copy for your records, ask us at info@holder.cloud and we will provide one.