ControllerThe client organisation.
ProcessorDBX ONE for the agreed service data.
PurposeSupplier-document, stock and management workflows.
Patient dataOutside the agreed scope.
1. Formation and instructions
This DPA forms part of the agreement when an authorised representative accepts it through a trial, implementation or continuation route. DBX ONE will process personal data only on the client's documented instructions, including the instructions inherent in using the agreed service, unless law requires otherwise.
2. Processing details
Subject matter: supplier-document processing, stock-management workflows, report preparation, support and related service administration.
Data: work contact details, supplier invoice/credit-note content, business correspondence, supplier/product details, STOCKROOM location and stock records, expiry/replenishment history, INSIGHTS evidence/review information and technical/audit data.
Data subjects: practice users, supplier contacts and other business contacts appearing in the submitted material.
Duration: for the service term and the applicable deletion/retention period.
3. Scope exclusions
The service is not intended for patient records, medical notes, prescription data or unrelated special-category personal data. The client must not deliberately submit those categories unless DBX ONE has separately agreed the processing in writing and the legal/security position has been updated.
4. Confidentiality
DBX ONE will limit access to people and service providers who need it for the agreed work and who are subject to appropriate confidentiality obligations. Client information will not be used for another client's operational work.
5. Security
DBX ONE will maintain appropriate technical and organisational measures for the nature of the service, including encrypted transport, authenticated access, private cloud storage, role restrictions, audit/security records and incident handling. The client remains responsible for its own user access, endpoint security and lawful instructions.
6. Sub-processors and current AI routes
| Provider | Purpose | Current route |
|---|
| Cloudflare | Hosting, Workers/Pages, D1, R2, Queues, Turnstile and configured AI/infrastructure services. | Core infrastructure for the public site and STOCKROOM. |
| OpenAI | AI-assisted supplier-document processing. | STOCKROOM may use the OpenAI API as a configured fallback. The current INSIGHTS manual route may use an individual ChatGPT consumer account with model improvement switched off; this consumer route is separately disclosed and is not represented as covered by an OpenAI business DPA. |
| Resend | Transactional/support email. | Email delivery. |
| Browser / operating-system push service | Opt-in STOCKROOM app notifications. | Used only where a user enables app notifications on a supported device/browser; the device/browser supplies the push endpoint used for delivery. |
| Zoho | Business correspondence. | DBX ONE mailbox/support handling. |
| Stripe | Payments where used. | Hosted payment processing, not supplier-document analysis. |
DBX ONE may replace or add sub-processors where reasonably necessary, provided the client is given the information required by applicable law and materially different live processing is not silently introduced.
7. OpenAI API data use
Where STOCKROOM uses the OpenAI API, DBX ONE relies on the API/business data controls applicable to that service. OpenAI states that API inputs and outputs are not used to train its models by default unless the organisation explicitly opts in. Default abuse-monitoring retention may apply subject to OpenAI's current platform controls and legal exceptions.
8. International transfers
Where a sub-processor processes personal data outside the UK, DBX ONE will rely on the transfer mechanism and contractual safeguards made available by that provider where required by UK data-protection law.
9. Assistance to the client
Taking account of the nature of the processing, DBX ONE will provide reasonable assistance with data-subject requests, security enquiries, DPIAs and regulator enquiries where the requested information relates to DBX ONE's processing and is reasonably available.
10. Personal-data breaches
DBX ONE will notify the client without undue delay after becoming aware of a personal-data breach affecting client data and will provide information reasonably available to support the client's own assessment and notification duties.
11. Return and deletion
At the end of the service, DBX ONE will delete or return client data as instructed, unless law requires retention. Provider-level backups, security logs and API/provider retention follow the relevant provider's documented lifecycle. Free-trial retention is described in the Privacy Notice and Confidentiality page.
12. Audit information
DBX ONE will make available information reasonably necessary to demonstrate compliance with processor obligations and will support proportionate audits or evidence requests subject to confidentiality, security, availability and reasonable notice.
13. Priority and law
If this DPA conflicts with the general Terms on a data-protection point, this DPA prevails to the extent required by law. England and Wales law applies unless mandatory data-protection law requires otherwise.