Schedule 1 to the CDRA Ltd Terms and Conditions · Last updated: July 2026
This Data Processing Addendum forms part of our Terms and Conditions. Capitalised and defined terms have the meanings given to them in the Terms and Conditions. References to “we” or “us” are to CDRA. References to “customer” are to you.
1.1 As data controller, you retain control of the Personal Data and remain responsible for your compliance obligations under the applicable Data Protection Legislation, including but not limited to providing any required notices and obtaining any required consents, and for the written processing instructions you give to us.
1.2 You shall ensure that you have all necessary appropriate consents and notices in place to enable lawful transfer of the Personal Data to us for the duration and purposes of Services so that we may lawfully use, process, and transfer the Personal Data in accordance with the Services.
1.3 You shall indemnify and keep indemnified CDRA against all losses, claims, damages, liabilities, fines, sanctions, interest, penalties, costs, charges and expenses (including reasonable legal and professional costs) arising out of or in connection with any failure by you to comply with your obligations under paragraphs 1.1 and 1.2 of this Schedule, including any failure to:
in each case to the extent required to enable the lawful processing, use, and transfer of Personal Data to CDRA for the purposes of the Services.
1.4 We shall only process (and shall ensure our personnel only process) the Personal Data in accordance with this addendum, except to the extent:
1.5 The processing of the Personal Data by us shall be for the subject-matter, duration, nature and purposes and involve the types of Personal Data and categories of Data Subjects set out in the Appendix to this addendum.
1.6 Taking into account the state of technical development and the nature of processing, we shall implement and maintain technical and organisational measures, including AES-256-GCM encryption, to protect the Personal Data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access.
1.7 We shall:
You authorise the appointment of Sub-Processors provided we comply at all times with the provisions of this clause 1.7.
1.8 We shall (at your cost):
1.9 We shall not process, transfer or otherwise disclose any Personal Data outside the United Kingdom without your prior written consent, except where such transfer is carried out in accordance with applicable Data Protection Laws and supported by appropriate safeguards. You acknowledge that Personal Data may be transferred outside of the United Kingdom via our sub-processors (including Anthropic and Supabase) pursuant to such safeguards.
1.10 We shall, in accordance with Data Protection Laws, make available to you such information that is in our possession or control as is necessary to demonstrate our compliance with the obligations placed on us under this clause 1.10 and to demonstrate compliance with the obligations on each party imposed by Article 28 of the GDPR (and under any equivalent Data Protection Laws equivalent to that Article 28), and allow for and contribute to audits, including inspections, by you (or another auditor you mandate) for this purpose (subject to a maximum of one audit request in any 12 month period).
1.11 We shall notify you without undue delay (and in any event within 24 hours) and in writing on becoming aware of any Personal Data Breach in respect of any Personal Data.
1.12 On the end of the provision of the Services relating to the processing of Personal Data, at your cost and our option, within 30 days we shall either return all of the Personal Data to you or securely dispose of the Data (and thereafter promptly delete all existing copies of it) except to the extent that any applicable law requires us to store such Personal Data.
1.13 This Schedule shall survive termination of the agreement:
Subject-matter of processing
The processing of Personal Data submitted to the CDRA App in connection with the provision of the Services to the customer.
Duration of the processing
For the duration of the customer's subscription for the Services plus a 30-day grace period upon termination or suspension of the Services.
Nature and purpose of the processing
Processing as reasonably required to provide the Services to the customer. The Services operate via two pathways: (i) storage only, where session and process notes are stored securely within Supabase and are not transmitted to any AI provider; and (ii) AI-assisted reflection, where notes are first processed through an automated de-identification layer and then through a clinical analysis engine (both provided by Anthropic) before being stored. The applicable pathway is determined by the customer at the point of use.
Type of Personal Data
Primarily pseudonymised client data. To the extent that data is not fully pseudonymised, this may include identifiers such as name, address, date of birth, and other information which may identify a client as inputted by the customer. Where the AI-assisted reflection pathway is used, data is additionally processed by Anthropic as a sub-processor; where the storage-only pathway is used, data is processed solely by Supabase as a sub-processor and is not transmitted to Anthropic or any other AI provider.
Categories of Data Subjects
Clients of the customer.
Special categories of Personal Data
Not intentionally processed. However, the Services may incidentally process health data where such information is inputted into the CDRA App by the customer.
CDRA Ltd · Company number 17310956 · Registered office: 11-12 Hallmark Trading Centre, Firth Way, Wembley, HA9 0LS
ICO registration number: ZC138142
Questions: d@davidwatermanpsychotherapist.co.uk