Data Processing Agreement
Last updated: 19 September 2026
This Data Processing Agreement (“DPA”) forms part of the agreement, subscription terms, order form or other contract (the “Agreement”) between the customer using the MogPharm Service (the “Controller”) and MogPharm Limited (the “Processor”), for the provision of the MogPharm platform and related services (the “Service”).
This DPA governs the processing of Personal Data by the Processor on behalf of the Controller and is intended to satisfy the requirements of the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and other applicable UK data-protection legislation, as amended from time to time.
Where there is any conflict between this DPA and the Agreement concerning the processing of Personal Data, this DPA will prevail.
1. Definitions and roles
For the purposes of this DPA:
“Data Protection Laws” means the UK GDPR, Data Protection Act 2018 and any other applicable UK legislation concerning privacy, data protection or the processing of Personal Data, as amended or replaced from time to time.
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Special Category Data” have the meanings given to them under applicable Data Protection Laws.
“Customer Data” means Personal Data submitted to, stored within or otherwise processed through the Service on behalf of the Controller.
1.1 Controller
The Controller determines the purposes and means of processing Customer Data, including the pharmacy, workforce, governance, compliance and operational information that it or its authorised users enter into the Service.
1.2 Processor
MogPharm processes Customer Data on behalf of the Controller only as necessary to provide, maintain, secure and support the Service and in accordance with the Controller’s documented instructions.
1.3 Independent controller activities
Where MogPharm processes Personal Data for its own legitimate business purposes — for example, account administration, billing, sales enquiries, website analytics or direct communications with its own customers — MogPharm may act as an independent Controller.
Such processing is governed by the MogPharm Privacy Policy.
2. Details of the processing
2.1 Subject matter
The provision of the MogPharm pharmacy compliance, governance, patient-safety and inspection-readiness platform.
2.2 Duration
Processing will take place for the duration of the Agreement and for any additional period reasonably required to return, export or securely delete Customer Data in accordance with this DPA or applicable law.
2.3 Nature and purpose of processing
MogPharm may collect, receive, store, organise, structure, retrieve, display, transmit, update, archive, back up and delete Customer Data for purposes including:
- providing and operating the Service;
- authenticating and managing authorised users;
- enabling pharmacy compliance and governance workflows;
- managing SOPs, policies, acknowledgements and training records;
- recording and managing near misses, incidents and patient-safety information;
- supporting pharmacy date-checking and medicines-governance activities;
- supporting controlled-drug governance workflows;
- maintaining Responsible Pharmacist and other operational records where applicable;
- providing inspection-readiness and compliance functionality;
- generating dashboards, reports, reminders and notifications;
- maintaining security, business continuity and system integrity;
- providing technical support; and
- performing other processing expressly instructed by the Controller through its use of the Service.
MogPharm will not process Customer Data for unrelated purposes unless required to do so by applicable law.
3. Categories of Personal Data
Depending on how the Controller uses the Service, Customer Data may include:
- names;
- work email addresses;
- work telephone numbers;
- job titles and professional roles;
- branch and organisation details;
- professional registration or qualification information where entered;
- user account and authentication information;
- staff training and competency records;
- SOP and policy acknowledgement records;
- compliance activity records;
- task assignments and completion records;
- audit-trail information;
- incident and near-miss records;
- medicines-governance information;
- controlled-drug governance information;
- pharmacy operational records;
- dates, timestamps and user activity associated with compliance records; and
- other Personal Data which the Controller or its authorised users choose to enter into the Service.
3.1 Special Category Data
The Service may, depending on the Controller’s use of particular functionality, process Special Category Data, including health-related information contained within incident, near-miss or other pharmacy governance records.
The Controller must ensure that any Special Category Data entered into the Service is necessary, proportionate and processed in accordance with applicable Data Protection Laws.
Users should avoid entering identifiable patient or other sensitive information unless it is necessary for the relevant purpose and permitted by the Controller’s policies and applicable law.
4. Categories of Data Subjects
Personal Data processed through the Service may relate to:
- pharmacists;
- pharmacy technicians;
- dispensing staff;
- healthcare assistants;
- delivery drivers;
- locum workers;
- trainees and apprentices;
- pharmacy managers;
- pharmacy owners and superintendents;
- contractors and other authorised personnel;
- patients or service users where information is legitimately included within pharmacy governance records;
- witnesses or other individuals referenced within controlled-drug or governance records; and
- other individuals referenced by the Controller within the Service.
5. Processor obligations
MogPharm shall:
5.1 Documented instructions
Process Customer Data only:
a. on the documented instructions of the Controller, including instructions arising from the Controller’s use and configuration of the Service; or
b. where processing is required by applicable law.
Where MogPharm is required by law to process Customer Data otherwise than on the Controller’s instructions, MogPharm will inform the Controller of that legal requirement before processing unless the law prohibits such notification.
MogPharm will inform the Controller if, in its reasonable opinion, an instruction infringes applicable Data Protection Laws.
5.2 Confidentiality
Ensure that persons authorised to process Customer Data:
- process it only where necessary for their duties;
- are subject to appropriate confidentiality obligations; and
- receive appropriate information or training concerning their data-protection responsibilities.
5.3 Security
Implement and maintain appropriate technical and organisational measures designed to protect Customer Data against:
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure;
- unauthorised access; and
- other unlawful processing.
Further information regarding these measures is contained in Section 10.
5.4 Data-subject requests
Taking into account the nature of the processing, provide reasonable assistance to the Controller through appropriate technical and organisational measures to enable the Controller to respond to requests by Data Subjects exercising their rights under applicable Data Protection Laws.
If MogPharm receives a request directly from a Data Subject concerning Customer Data, MogPharm will notify the Controller unless legally prohibited from doing so.
MogPharm will not independently respond to such a request except:
- on the Controller’s documented instructions; or
- where required by applicable law.
5.5 Compliance assistance
Taking into account the nature of the processing and information available to MogPharm, provide reasonable assistance to the Controller in complying with its obligations relating to:
- security of processing;
- Personal Data Breach assessment and notification;
- notification to affected Data Subjects where required;
- Data Protection Impact Assessments;
- prior consultation with the Information Commissioner’s Office where required; and
- other obligations under Articles 32–36 of the UK GDPR, where applicable.
5.6 Records and regulatory cooperation
Maintain such records relating to processing activities as are required of MogPharm under applicable Data Protection Laws and reasonably cooperate with competent supervisory authorities where legally required.
6. Controller obligations
The Controller is responsible for:
a. determining the lawful basis and purpose for processing Customer Data;
b. ensuring that Personal Data entered into the Service has been collected and disclosed lawfully;
c. providing all required privacy information to Data Subjects;
d. ensuring that its instructions to MogPharm comply with applicable Data Protection Laws;
e. determining appropriate retention periods for pharmacy and governance information;
f. ensuring that users enter only Personal Data that is reasonably necessary for the relevant purpose;
g. appropriately managing user accounts, permissions and access within its organisation;
h. promptly removing access for persons who are no longer authorised to use the Service;
i. maintaining the confidentiality of its users’ credentials;
j. ensuring that Special Category Data is processed only where an appropriate lawful condition applies; and
k. complying with any professional, regulatory, NHS, GPhC or other sector-specific obligations applicable to the Controller’s own activities.
The Controller warrants that it is entitled to provide Customer Data to MogPharm and to instruct MogPharm to process it as described in this DPA.
7. Sub-processors
7.1 General authorisation
The Controller provides general written authorisation for MogPharm to engage third-party processors (“Sub-processors”) where reasonably required to provide the Service.
MogPharm will ensure that each Sub-processor processing Customer Data is subject to written contractual obligations providing a level of data protection substantially equivalent to the obligations applicable to MogPharm under this DPA, to the extent required by applicable Data Protection Laws.
MogPharm remains responsible to the Controller for the performance of its Sub-processors’ data-protection obligations to the extent required by applicable law.
7.2 Current principal Sub-processors
| Sub-processor | Purpose | Primary processing/location information |
|---|---|---|
| Supabase | Database infrastructure, authentication and file storage | MogPharm production database intended to be hosted in the United Kingdom (London / AWS eu-west-2), subject to production configuration |
| Vercel | Application hosting, server-side functions and content delivery | Global infrastructure. Function processing location depends on MogPharm’s Vercel configuration |
| Resend | Transactional and notification email delivery | May involve processing in the United States and other jurisdictions through Resend and its authorised sub-processors |
MogPharm may update its Sub-processor arrangements from time to time.
7.3 Changes to Sub-processors
MogPharm will make information regarding material changes to Sub-processors available to the Controller and will provide reasonable advance notice where practicable.
The Controller may object to the appointment of a new Sub-processor on reasonable and documented data-protection grounds.
Where such an objection cannot reasonably be resolved, the parties will work in good faith to identify an appropriate solution, which may include restricting the affected processing or terminating the affected Service in accordance with the Agreement.
8. International transfers
MogPharm intends to host its primary production database in the United Kingdom.
However, certain Sub-processors or their service providers may process or access Customer Data outside the United Kingdom.
Where MogPharm makes or permits a restricted transfer of Personal Data outside the United Kingdom, MogPharm will ensure that an appropriate lawful transfer mechanism is in place as required under applicable Data Protection Laws.
Depending on the relevant transfer, these safeguards may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses;
- binding corporate rules; or
- another legally recognised transfer mechanism.
Where required, MogPharm will take reasonable steps to ensure that the applicable data-protection test or transfer risk assessment requirements have been addressed.
9. Personal Data Breaches
MogPharm will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
Where information is reasonably available, the notification will include:
- the nature of the Personal Data Breach;
- the categories of Personal Data affected;
- the categories and approximate number of Data Subjects affected, where known;
- the likely consequences of the breach;
- measures taken or proposed to contain, mitigate or remediate the breach; and
- a contact point for further information.
Where all information is not immediately available, MogPharm may provide it in phases as information becomes available.
MogPharm will take reasonable steps to investigate, contain and mitigate Personal Data Breaches affecting Customer Data.
Nothing in this clause requires MogPharm to make an assessment on behalf of the Controller as to whether the Controller is required to notify the Information Commissioner’s Office or affected Data Subjects.
10. Technical and organisational security measures
MogPharm will maintain technical and organisational measures appropriate to the nature of the Customer Data and the risks associated with its processing.
These measures may include, as applicable:
Access controls
- role-based access according to user permissions;
- least-privilege access principles;
- authentication controls;
- restricted administrative access;
- controlled access to production systems; and
- procedures for removing access when no longer required.
Database and tenant security
- logical segregation of customer environments and records;
- database row-level security controls where applicable;
- access policies designed to prevent users from accessing data outside their authorised organisation or role; and
- restrictions on privileged database credentials.
Encryption
- encrypted transmission of information using TLS or equivalent secure transport mechanisms; and
- encryption at rest through relevant infrastructure providers where supported.
Application and operational security
- separation of production, development, staging or demonstration data where appropriate;
- controlled deployment processes;
- restricted access to application secrets and credentials;
- monitoring of material administrative or security events where implemented;
- vulnerability and dependency management appropriate to the Service; and
- reasonable procedures for responding to security incidents.
Business continuity and recovery
- infrastructure-level backup arrangements;
- reasonable restoration and recovery procedures;
- periodic review of backup arrangements; and
- measures intended to maintain availability and resilience of the Service.
The specific technical implementation of security measures may change as technology, risks and the Service develop, provided that MogPharm does not materially reduce the overall level of protection for Customer Data during the term of the Agreement.
11. Data retention, return and deletion
Customer Data will be retained for the duration of the Controller’s use of the Service and in accordance with:
- the Controller’s instructions;
- applicable retention settings;
- the legitimate operation of the Service; and
- applicable legal or regulatory requirements.
The Controller remains responsible for determining the legally appropriate retention periods for records it creates through the Service.
Upon termination or expiry of the Agreement, and at the Controller’s choice where reasonably practicable, MogPharm will:
a. return or make available an export of Customer Data; and/or
b. delete Customer Data,
unless applicable law requires continued storage.
MogPharm may retain Customer Data contained within secure backups until those backups expire or are overwritten in accordance with the applicable backup cycle, provided that the data remains protected and is not used for another purpose.
12. Audits and compliance information
MogPharm will make available to the Controller information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the UK GDPR.
Subject to appropriate confidentiality, security and access restrictions, MogPharm will permit and reasonably contribute to audits or inspections conducted by the Controller or an independent auditor appointed by the Controller.
Unless required following a Personal Data Breach, regulatory request or material compliance concern:
- audits should normally be conducted no more than once in any 12-month period;
- the Controller should provide reasonable advance written notice;
- audits should take place during normal business hours;
- audits must not compromise the confidentiality or security of other customers or MogPharm systems; and
- each party will bear its own costs unless otherwise agreed.
Where appropriate, MogPharm may satisfy audit requests initially by providing relevant security, compliance or independent assessment documentation.
13. Liability and statutory responsibilities
Nothing in this DPA relieves either party of its own responsibilities or liabilities under applicable Data Protection Laws.
Where MogPharm processes Customer Data outside the Controller’s lawful documented instructions and determines the purposes and means of that processing, MogPharm may be treated as a Controller in respect of that processing to the extent provided by applicable Data Protection Laws.
Any contractual limitations of liability contained in the Agreement will apply to this DPA to the extent permitted by law.
14. Changes to this DPA
MogPharm may update this DPA where reasonably necessary to:
- reflect changes in Data Protection Laws;
- reflect regulatory guidance;
- accommodate changes to the Service or Sub-processors;
- improve data-protection or security arrangements; or
- address changes in applicable transfer mechanisms.
MogPharm will not materially reduce the protections applying to Customer Data during an existing subscription term without reasonable justification.
Material changes will be notified to customers through an appropriate communication channel.
15. Governing law
This DPA and any dispute or claim arising out of or in connection with it are governed by the laws of England and Wales.
The courts of England and Wales will have jurisdiction, subject to any mandatory rights or remedies arising under applicable Data Protection Laws.
16. Contact
Questions concerning this DPA, data protection or the processing of Customer Data may be directed to:
MogPharm
MogPharm Limited
Email: privacy@mogpharm.com
Registered office: Suite RA01, 195-197 Wood Street, London, E17 3NU
Company number: 15829054