Data processing agreement

Version 1.0 · Last updated 16 September 2026

The terms under which HeraIQ processes personal data for the care providers that use it, as Article 28 of the UK GDPR requires. They form part of our terms of service.

About this agreement

This data processing agreement forms part of our terms of service. It applies whenever we process personal data on behalf of a care provider that uses HeraIQ. By accepting the terms, the organisation accepts this agreement too.

In this agreement, “we” and “HeraIQ” mean HERA INTELLIGENCE LTD, and “you” means the organisation that holds the HeraIQ account. “Data protection law” means the UK GDPR and the Data Protection Act 2018. Words such as controller, processor, personal data, processing, data subject and personal data breach have the meaning they have in the UK GDPR. “Customer personal data” means the personal data described in Annex 1 that we process for you. “Your notice address” means the email address of the person who accepted the terms of service for your organisation, or another address you give us in writing, as the terms of service set out.

This agreement is written to meet Article 28 of the UK GDPR.

Who we are

HeraIQ is a trading name of HERA INTELLIGENCE LTD, a company registered in England and Wales (company number 17459930).

Registered office: as shown on the Companies House register

Our ICO registration reference will be published here once issued.

Contact: hello@heraiq.io

Who is responsible for what

You are the controller of customer personal data, and we are your processor. Customer personal data is everything held in your account about the people you care for and the people who work for you, including:

  • service-user records, such as identity and contact details, health and care needs, risks, medication information, DNAR status, NHS number, next of kin and GP details, capacity and safeguarding information, care plans, risk assessments and visit notes;
  • the staff records you hold as an employer, such as identity and contact details, rotas and visits, check-in and check-out location evidence, training, DBS certificate details, and right-to-work and identity documents;
  • messages sent in your account, and conversations with Hera about your service.

Annex 1 describes this processing in full.

What we do as a controller

Some processing is for our own purposes, and for it we are the controller, not your processor. This agreement does not cover it. Our privacy notice explains it. It is:

  • the account details of your managers and office staff, such as name, work email, organisation, site and CQC location ID, which we use to run the account;
  • a carer’s own account, profile and document cabinet, which the carer keeps across employers. The records you hold about that carer as their employer remain customer personal data;
  • sign-in security and the operation of the service, including sign-in cookies, second-factor codes and AI usage metering;
  • AI misuse flags. When Hera declines a request as off-topic, we keep up to 500 characters of the message, with the user’s account, organisation, the part of the product it came from and the AI model, for 180 days. Only HeraIQ staff can see these. After a person has reviewed a flag, our staff can escalate it or block the account;
  • support requests you or your users send us.

Processing only on your instructions

We process customer personal data only on your documented instructions, including instructions about transferring it outside the United Kingdom. The one exception is where UK law requires us to process it. If that happens, we will tell you before we process it, unless that law forbids telling you on important grounds of public interest.

Your documented instructions are:

  • the terms of service and this agreement;
  • how you and your users set up and use HeraIQ, including what you record, the features you switch on and what you ask Hera to do;
  • any other written instruction you give us that we agree is consistent with the terms.

We will tell you straight away if we believe an instruction infringes data protection law. We may pause the processing that instruction concerns until you confirm, change or withdraw it.

We do not sell customer personal data. We do not use it to train AI models, and we do not use your content as examples for other customers. We do not use it for any purpose other than providing the service to you, apart from the controller purposes listed under Who is responsible for what.

Confidentiality of our people

Everyone we authorise to process customer personal data is bound by a duty of confidentiality, either by contract or by law. We give access only to people who need it to provide, support or secure the service, and only to the extent they need it.

Security

We take the measures Article 32 of the UK GDPR requires, appropriate to the risk of the processing. Annex 2 sets out what is in place. It also sets out, just as plainly, what is not yet in place, so that you can take those limits into account in your own assessment of whether HeraIQ is suitable for your service.

We may update these measures as the service develops, but we will not lower the overall level of protection Annex 2 describes. Security problems can be reported to security@heraiq.io.

Sub-processors

You give us general written authorisation to use the sub-processors on our sub-processor list. Annex 3 reproduces that list as it stood when this version of the agreement was published.

The list names the sub-processors we engage directly. Before we add or replace one of them, we will email your notice address at least 30 days in advance. The email will say who the sub-processor is, what it will do and where it will process data. We will update the list on the same day.

Our sub-processors may use other companies in turn, and may change them at shorter notice than we give you. When a sub-processor tells us about such a change, we will pass it on to you by email to your notice address without undue delay.

You may object to either kind of change on reasonable data protection grounds by emailing hello@heraiq.io within 30 days of our email. We will discuss the objection with you in good faith. If we cannot resolve it, you may end your subscription, before the change takes effect where it has not yet done so. Any refund follows our refund policy.

Each sub-processor is bound by a written contract that imposes the data protection obligations Article 28(4) of the UK GDPR requires, including sufficient guarantees that it will take appropriate technical and organisational measures. We remain fully liable to you for each sub-processor’s performance of those obligations, subject to Liability.

International transfers

Your database is hosted in London. Some sub-processors process customer personal data outside the United Kingdom, as Annex 3 shows. AI processing by OpenAI runs on OpenAI’s standard infrastructure, not in a UK or EU data residency region.

We transfer customer personal data outside the United Kingdom, or allow a sub-processor to do so, only in a way that meets Chapter V of the UK GDPR. That means the transfer relies on UK adequacy regulations, including the UK Extension to the EU-U.S. Data Privacy Framework for a certified recipient, or on an appropriate safeguard such as the International Data Transfer Agreement or the International Data Transfer Addendum to the EU Standard Contractual Clauses.

By accepting this agreement, you instruct us to make the transfers Annex 3 describes, using the safeguard shown for each sub-processor.

Helping with people’s rights

People whose data is in your account may exercise their rights under data protection law, such as access, correction, erasure, restriction, objection and data portability. You are responsible for responding to them. Taking into account the nature of the processing, we help you with appropriate technical and organisational measures, as far as that is possible.

Where HeraIQ does not let you do something yourself, such as putting together a copy of everything held about one person, tell us and we will help. We do not charge for this when the request is reasonable.

If someone sends us a request about customer personal data, we will pass it to you without undue delay. We will not answer it ourselves, except to tell the person that we have passed it to you.

Personal data breaches

We will tell you about a personal data breach affecting customer personal data without undue delay, and in any case within 48 hours of becoming aware of it. We will send the notice by email to your notice address.

The notice will include what we know at the time, and we will send the rest as we learn it:

  • what happened, and whether it affects the confidentiality, integrity or availability of the data;
  • the categories and approximate number of people affected, and the categories and approximate number of records;
  • the likely consequences;
  • what we have done, and plan to do, to contain the breach and reduce its effects;
  • who you can contact at HeraIQ for more information.

We will take reasonable steps to contain and investigate the breach and to limit the harm, and we will work with you so that you can meet your own duties to tell the Information Commissioner’s Office and the people affected. We will not notify the regulator or the people affected on your behalf unless you ask us to or the law requires it.

Security, impact assessments and prior consultation

Taking into account the nature of the processing and the information available to us, we help you meet your obligations under Articles 32 to 36 of the UK GDPR:

  • keeping personal data secure (Article 32);
  • notifying personal data breaches to the regulator and to the people affected (Articles 33 and 34);
  • carrying out a data protection impact assessment (Article 35);
  • consulting the Information Commissioner’s Office before processing that an assessment shows would be high risk (Article 36).

What that help looks like

We answer reasonable questions about how HeraIQ processes data, its sub-processors, its security measures and its AI features, so that you can complete your own assessment. We do not charge for this when the request is reasonable.

Deleting or returning data at the end

When your subscription ends, you have 90 days to ask us in writing for a copy of customer personal data. HeraIQ does not yet have a self-service export of a whole organisation’s data, so we will provide one within 30 days of your written request.

After those 90 days, we delete customer personal data within 30 days, unless UK law requires us to keep it. If you tell us in writing that you want it deleted sooner, we will delete it within 30 days of your instruction. When you ask, we will confirm in writing that deletion from HeraIQ’s own systems is complete.

Copies can remain for a limited time after that in database backups, which age out as the table below shows, and in sub-processors’ own logs, which each sub-processor deletes on its own schedule. For example, OpenAI keeps abuse-monitoring logs for up to 30 days, and LangSmith keeps its records of AI requests for up to 400 days.

What happens to customer personal data after a subscription ends
DataKept forNotes
Customer data after a subscription ends90 days to request an export, then deleted within 30 daysBackup copies then age out on their own schedules, which depend on where each copy is held. We will confirm the current periods in writing on request.

A carer’s own account, profile and document cabinet belong to the carer, so they are not deleted when your subscription ends. The records you hold about that carer as their employer are.

Information and audits

We will make available to you the information you need to show that we meet our obligations under Article 28 of the UK GDPR. That includes this agreement, its annexes, our sub-processor list and answers to reasonable security questions.

We will allow, and contribute to, audits and inspections carried out by you or by an auditor you appoint, on these terms:

  • one audit a year;
  • on reasonable written notice;
  • at your cost;
  • under a duty of confidentiality, and in a way that does not expose other customers’ data or weaken the security of the service.

The limit of one a year does not apply to an audit or inspection that the Information Commissioner’s Office or another regulator requires, or to an additional audit after a personal data breach affecting customer personal data.

Your responsibilities as controller

As controller, you are responsible for:

  • your CQC registration, and your duties under Regulation 17 to keep accurate, complete records;
  • having a lawful basis for the processing, and a condition for health data and for criminal offence data such as DBS certificate details;
  • giving your own privacy information to the people you care for and to your staff;
  • carrying out your own data protection impact assessment for your use of HeraIQ;
  • making sure the data you record is accurate, and that your instructions to us are lawful;
  • having a competent person review and approve what Hera drafts before you rely on it;
  • managing who can use your account, and removing access when someone leaves;
  • using HeraIQ only for adult services. Do not record people under 18.

Liability

The limits and exclusions of liability in our terms of service apply to this agreement. They apply to the terms and this agreement together, not to each separately. In summary, liability is capped at the greater of the fees paid in the 12 months before the claim or £5,000. There is no cap on, or exclusion of, liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot legally be limited. If this summary and the terms of service differ, the terms of service apply.

Nothing in this agreement limits either party’s liability to a data subject or to the Information Commissioner’s Office.

If documents conflict

The annexes form part of this agreement. If documents conflict, they take priority as the terms of service also set out:

  • this agreement, on anything to do with the protection of personal data;
  • an Order, as the terms of service define it, on your plan and fees;
  • the terms of service, on everything else.

How long this agreement lasts, and changes

This agreement lasts for as long as we process customer personal data for you, including the export and deletion period after your subscription ends.

We will give you at least 30 days’ notice of any change to this agreement by email to your notice address. Each version is dated, and the version number appears at the top of this page.

The law of England and Wales governs this agreement, and the courts of England and Wales have jurisdiction, as the terms of service set out. Notices under this agreement go to hello@heraiq.io.

Annex 1: Details of the processing

Subject matter

Providing HeraIQ to you: care records, care planning, rotas and visits, staff records, messaging and the Hera AI assistant.

Duration

For as long as your subscription lasts, and afterwards until customer personal data is deleted as set out in Deleting or returning data at the end.

Nature of the processing

Storing, organising, retrieving and showing data to your authorised users; AI processing, including drafting, transcription, reading documents, speech, image generation and embeddings; sending emails and push notifications; backup; and deletion.

Purpose

To provide, support and secure HeraIQ for you, as the terms of service describe. HeraIQ is an administrative and documentation tool. It drafts care plans, risk assessment records, rotas and policies from the information you record, for your staff to review and approve.

Categories of data subjects

  • people who receive care from you;
  • their next of kin, representatives and other contacts;
  • their GPs and other professionals involved in their care;
  • your staff, including carers, office staff and managers.

Categories of personal data

  • About the people you care for: identity and contact details, health and care needs, risks, medication information, DNAR status, NHS number, next of kin and GP details, capacity and safeguarding information, care plans, risk assessments and visit notes.
  • About your staff: identity and contact details, rotas and visits, check-in and check-out location evidence, training records, DBS certificate details, and right-to-work and identity documents.
  • About contacts and professionals: names, their relationship to the person, and contact details.
  • Messages sent in your account, and conversations with Hera about your service.

Special category data

Health data about the people you care for. Also any other special category data that you or your staff record in notes or documents.

Criminal offence data

DBS certificate details about your staff, including the certificates themselves when they are uploaded and read by AI.

Adult services only

HeraIQ is for adult social care. You must not record people under 18.

Annex 2: Technical and organisational measures

What is in place

  • Separation between organisations. Row-level security in the database separates one organisation’s data from another’s for data read from the browser and by the carer assistant. Our backend servers use a privileged database connection, so on those requests the server takes your organisation and role from the verified sign-in and checks them before acting.
  • AI changes wait for a person. Hera prepares changes to clinical, identity, status or rota records as confirmations, which a named person reviews and applies. Cancelling visits, closing a concern and a manager confirming attendance also need a typed reason. Four preference fields on a person’s record (preferred name, pronouns, preferred language and access notes) save straight away and are logged with their previous value. Hera’s own memories and reminders also save straight away, and a user can ask Hera to forget a memory. Hera can also run the organisation’s own CQC self-audit, and set how often it runs, without asking first; a run records a reading and a draft report and changes no care record.
  • An audit trail of changes made through Hera. It records who acted and what they did, and for supported actions it keeps the state of the record before the change. Undoing a change adds a new entry rather than deleting the original.
  • Private file storage. Files are held in private storage and reached only through signed links that expire within 30 minutes.
  • Upload checks. Our server works out what each uploaded file really is from its contents, not from its name or the type the uploader’s device claims, and does not keep files of a type we do not accept. Staff and carer documents first land in a quarantine area that no one can read, and the server then stores or deletes them.
  • Encryption in transit. Connections use TLS, and the site sends HTTP Strict Transport Security, so browsers connect only over HTTPS.
  • A restricted staff console. HeraIQ’s internal console is open only to named staff with a HeraIQ email address on an allow-list, who must complete a second sign-in step.
  • UK hosting. The database is hosted in London, United Kingdom.

What is not in place yet

  • We hold no ISO 27001 or SOC 2 certification and no Cyber Essentials certificate, and we have not completed the Data Security and Protection Toolkit (DSPT).
  • No independent penetration test has been carried out.
  • Two-factor sign-in for your users is built but not yet enforced. Sign-in today is by email and password.
  • Stored files, such as uploaded documents and photos, are not yet included in backups.
  • We do not yet keep a record of who viewed a record.
  • There is no DCB0129 clinical safety case, and no Clinical Safety Officer has been appointed.
  • AI processing is not in a UK or EU region. Annex 3 gives the details.

Annex 3: Sub-processors

These are the sub-processors you authorise under Sub-processors. The current list is always on our sub-processor page, and changes follow the notice process in that clause.

Sub-processors authorised under this agreement
Sub-processorWhat it doesDataLocationTransfer safeguardSource
Supabase Pte. LtdDatabase, sign-in and file storage.Everything held in a customer's account, account details and uploaded files.London, United Kingdom (AWS eu-west-2). Supabase may process some data, such as logs and metrics, outside that region where needed to provide the service.EU Standard Contractual Clauses with the UK Addendum.Supabase DPA
Vercel Inc.Hosting for the website, the app and its server functions.Requests to the website and app as they are handled, and request logs.Server functions run in London, United Kingdom (lhr1). Vercel's primary processing facilities are in the United States.UK International Data Transfer Addendum (IDTA).Vercel DPA
OpenAI OpCo, LLCAI processing: chat, realtime voice sent straight from the browser, transcription, reading documents (including identity documents and DBS certificates), speech, image generation and embeddings.The text, audio, images and documents a request needs, which can include care record details.OpenAI's standard infrastructure, not a UK or EU data residency region. OpenAI keeps abuse-monitoring logs for up to 30 days, and does not use API data to train its models by default.EU Standard Contractual Clauses with the UK Addendum.OpenAI DPA
LangChain, Inc. (LangSmith)Monitoring Hera's AI so that we can find and fix problems: a record of each AI request, the steps and tools it used, and its answer.What an AI request contained and returned, including the records Hera looked up, which can include care record details.LangSmith's EU region, hosted on Google Cloud in the European Union. If HeraIQ is ever pointed at LangSmith anywhere else, this monitoring switches itself off. Records are kept for up to 400 days.EU Standard Contractual Clauses with the UK Addendum.LangChain DPA
Plus Five Five, Inc. (Resend)Sending transactional email.Recipient email addresses, the emails we send and delivery logs.United States.EU Standard Contractual Clauses with the UK Addendum.Resend DPA
650 Industries, Inc. (Expo)Delivering push notifications to the HeraIQ Care app, passed on to Apple Push Notification service and Firebase Cloud Messaging.A device push token and generic notification text, such as "You have a new message." No care content.United States.UK Extension to the EU-U.S. Data Privacy Framework.Expo privacy policy