← Back to Terms & Conditions

Data Processing Addendum

Schedule 1 to the CDRA Ltd Terms and Conditions · Last updated: July 2026

This Data Processing Addendum forms part of our Terms and Conditions. Capitalised and defined terms have the meanings given to them in the Terms and Conditions. References to “we” or “us” are to CDRA. References to “customer” are to you.

Controller obligations

1.1 As data controller, you retain control of the Personal Data and remain responsible for your compliance obligations under the applicable Data Protection Legislation, including but not limited to providing any required notices and obtaining any required consents, and for the written processing instructions you give to us.

1.2 You shall ensure that you have all necessary appropriate consents and notices in place to enable lawful transfer of the Personal Data to us for the duration and purposes of Services so that we may lawfully use, process, and transfer the Personal Data in accordance with the Services.

1.3 You shall indemnify and keep indemnified CDRA against all losses, claims, damages, liabilities, fines, sanctions, interest, penalties, costs, charges and expenses (including reasonable legal and professional costs) arising out of or in connection with any failure by you to comply with your obligations under paragraphs 1.1 and 1.2 of this Schedule, including any failure to:

  • provide appropriate privacy notices to your clients; or
  • obtain all necessary consents or satisfy an alternative lawful basis for processing, including (where applicable) meeting a valid condition under Article 9 of the UK GDPR for the processing of any data which may constitute special category data,

in each case to the extent required to enable the lawful processing, use, and transfer of Personal Data to CDRA for the purposes of the Services.

Instructions

1.4 We shall only process (and shall ensure our personnel only process) the Personal Data in accordance with this addendum, except to the extent:

  • that alternative processing instructions are agreed between us in writing; or
  • we are otherwise required by applicable law (and shall inform you of that legal requirement before processing, unless applicable law prevents us doing so on important grounds of public interest); and
  • without prejudice to any other term in this Data Processing Addendum or our Conditions, if we believe that any instruction is likely to infringe the Data Protection Laws we shall promptly inform you and be entitled to cease to provide the relevant Services until we have agreed appropriate amended instructions which are not infringing.

1.5 The processing of the Personal Data by us shall be for the subject-matter, duration, nature and purposes and involve the types of Personal Data and categories of Data Subjects set out in the Appendix to this addendum.

Security

1.6 Taking into account the state of technical development and the nature of processing, we shall implement and maintain technical and organisational measures, including AES-256-GCM encryption, to protect the Personal Data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access.

Sub-processing and personnel

1.7 We shall:

  • prior to the relevant Sub-Processor carrying out any processing activities in respect of the Personal Data, appoint each Sub-Processor under a written contract containing materially the same obligations as under this Data Protection Addendum (including those relating to sufficient guarantees to implement appropriate technical and organisational measures) that is enforceable by us and ensure each such Sub-Processor complies with all such obligations;
  • remain fully liable to you under the Conditions for all the acts and omissions of each Sub-Processor as if they were our own; and
  • ensure that all persons engaged by us or any Sub-Processor to process Personal Data are subject to a binding written contractual obligation to keep the Personal Data confidential.

You authorise the appointment of Sub-Processors provided we comply at all times with the provisions of this clause 1.7.

Assistance

1.8 We shall (at your cost):

  • assist you in ensuring compliance with your obligations pursuant to Articles 32 to 36 of the GDPR (and any similar obligations under applicable Data Protection Laws) taking into account the nature of the processing and the information available to us; and
  • taking into account the nature of the processing, assist you (by appropriate technical and organisational measures), insofar as this is possible, for the fulfilment of your obligations to respond to requests for exercising the Data Subjects' rights under Chapter III of the UK GDPR (and any similar obligations under applicable Data Protection Laws) in respect of any Personal Data.
  • refer to you all requests we receive for exercising any Data Subjects' rights under Chapter III of the GDPR which relate to any Personal Data. It shall be your responsibility to reply to all such requests as required by applicable law.

International transfers

1.9 We shall not process, transfer or otherwise disclose any Personal Data outside the United Kingdom without your prior written consent, except where such transfer is carried out in accordance with applicable Data Protection Laws and supported by appropriate safeguards. You acknowledge that Personal Data may be transferred outside of the United Kingdom via our sub-processors (including Anthropic and Supabase) pursuant to such safeguards.

Audits and processing

1.10 We shall, in accordance with Data Protection Laws, make available to you such information that is in our possession or control as is necessary to demonstrate our compliance with the obligations placed on us under this clause 1.10 and to demonstrate compliance with the obligations on each party imposed by Article 28 of the GDPR (and under any equivalent Data Protection Laws equivalent to that Article 28), and allow for and contribute to audits, including inspections, by you (or another auditor you mandate) for this purpose (subject to a maximum of one audit request in any 12 month period).

Breach

1.11 We shall notify you without undue delay (and in any event within 24 hours) and in writing on becoming aware of any Personal Data Breach in respect of any Personal Data.

Deletion / return

1.12 On the end of the provision of the Services relating to the processing of Personal Data, at your cost and our option, within 30 days we shall either return all of the Personal Data to you or securely dispose of the Data (and thereafter promptly delete all existing copies of it) except to the extent that any applicable law requires us to store such Personal Data.

Survival

1.13 This Schedule shall survive termination of the agreement:

  • indefinitely in the case of clause 1.11 of this Schedule (breach notification); and
  • in the case of all other paragraphs and provisions of this Schedule, until the later of: the termination or expiry of this agreement; or return or secure deletion or disposal of the last of the Personal Data in our (or any of our Sub-Processor's) possession or control in accordance with this agreement.

Appendix — Data processing details

Subject-matter of processing

The processing of Personal Data submitted to the CDRA App in connection with the provision of the Services to the customer.

Duration of the processing

For the duration of the customer's subscription for the Services plus a 30-day grace period upon termination or suspension of the Services.

Nature and purpose of the processing

Processing as reasonably required to provide the Services to the customer. The Services operate via two pathways: (i) storage only, where session and process notes are stored securely within Supabase and are not transmitted to any AI provider; and (ii) AI-assisted reflection, where notes are first processed through an automated de-identification layer and then through a clinical analysis engine (both provided by Anthropic) before being stored. The applicable pathway is determined by the customer at the point of use.

Type of Personal Data

Primarily pseudonymised client data. To the extent that data is not fully pseudonymised, this may include identifiers such as name, address, date of birth, and other information which may identify a client as inputted by the customer. Where the AI-assisted reflection pathway is used, data is additionally processed by Anthropic as a sub-processor; where the storage-only pathway is used, data is processed solely by Supabase as a sub-processor and is not transmitted to Anthropic or any other AI provider.

Categories of Data Subjects

Clients of the customer.

Special categories of Personal Data

Not intentionally processed. However, the Services may incidentally process health data where such information is inputted into the CDRA App by the customer.

CDRA Ltd · Company number 17310956 · Registered office: 11-12 Hallmark Trading Centre, Firth Way, Wembley, HA9 0LS

ICO registration number: ZC138142

Questions: d@davidwatermanpsychotherapist.co.uk