Legal

Data Processing Agreement

Last updated: 26 May 2026

This page summarises the Data Processing Agreement ("DPA") that Neutropy Ltd. ("Neutropy", "we", "us"), provider of an autonomous operating system for healthcare services through our agentic platform, enters into with operating clinics and hospitals ("Controllers") under Article 28 of the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"). The signed DPA is the legally binding document; the summary below describes its substance for the avoidance of doubt.

A signed copy of the current DPA is available on request. Email luke@neutropy.ai and we'll send it back the same day.

1. Roles

The operating clinic is the Controller for patient personal data processed through the Neutropy scheduler. Neutropy acts as the Processor, processing personal data only on documented instructions from the Controller.

2. Scope of processing

  • Subject matter: patient scheduling workflows, outbound patient communications, and appointment management within the Controller's practice management system.
  • Duration: for the term of the Master Services Agreement, plus the agreed retention window.
  • Categories of data subjects: patients of the operating clinic; referring GPs; clinic staff.
  • Categories of personal data: contact details, demographic data, special-category health data within the meaning of GDPR Art. 9(1).

3. Sub-processors

Neutropy uses a small set of vetted sub-processors, all EU-resident for patient data. The current list is available on request from luke@neutropy.ai. Controllers are notified at least 30 days in advance of any change.

4. Security measures

  • EU-resident infrastructure; no patient data leaves the EEA.
  • Personal identifiers are isolated from AI processing components. No raw patient identifiers are exposed to third-party model providers.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access control and signed audit logging on every read/write of patient data.
  • Annual penetration testing; documented incident-response and breach-notification procedures.

5. International transfers

Patient personal data is processed and stored exclusively on EU-resident infrastructure. Where any sub-processor processes operational telemetry containing no patient identifiers, that processing is also EU-resident unless otherwise agreed in writing.

6. Data subject requests

Neutropy will assist the Controller in responding to requests from data subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection) within the timelines required by law.

7. Audit rights

The Controller may audit Neutropy's compliance with this DPA once per calendar year on reasonable notice, or more frequently following a personal data breach. Audits may be conducted by the Controller or a mutually agreed third-party auditor under appropriate confidentiality terms.

8. Breach notification

Neutropy will notify the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Controller's data, providing the information required by GDPR Art. 33.

9. Return or deletion on termination

At the Controller's choice, Neutropy will return or securely delete all personal data processed under the agreement within 30 days of termination, unless retention is required by Union or Irish law.

10. Contact

For the signed DPA, or any questions about how we process patient data, email luke@neutropy.ai.