Legal
Data Processing Agreement
Last updated: September 2026
This Data Processing Agreement ("DPA") supplements the Master Services Agreement or Order Form between Renvia Ltd ("Processor") and the healthcare provider or payer customer ("Controller"). It governs Renvia's processing of Personal Data on behalf of the Controller under the UK GDPR and the Data Protection Act 2018.
1. Subject matter & duration
Renvia processes Personal Data for the sole purpose of providing the remote cardio-renal-metabolic monitoring service, for the duration of the underlying agreement plus a defined return/deletion window.
2. Nature and purpose of processing
- Enrolment of patients into remote monitoring pathways under clinical direction.
- Ingestion, storage and display of physiological readings from paired home devices.
- Risk stratification and clinician-facing prioritisation, with clinician-in-the-loop escalation.
- Audit logging, security monitoring, and service telemetry.
3. Categories of data subjects
- Patients enrolled by the Controller.
- Clinicians and facility administrators authorised by the Controller.
4. Types of Personal Data
- Identifiers (name, NHS number where provided, date of birth, contact details).
- Special category health data (diagnoses, vital signs, medication context).
- Account and authentication metadata for platform users.
5. Renvia's obligations as Processor
- Process Personal Data only on documented instructions from the Controller.
- Ensure personnel are bound by confidentiality obligations.
- Implement the technical and organisational measures set out in our Security overview.
- Assist the Controller in fulfilling data subject rights requests and DPIAs.
- Notify the Controller without undue delay (and in any event within 24 hours) of any confirmed Personal Data breach.
- Delete or return Personal Data at the end of the service term, per the Data Retention Schedule.
6. Sub-processors
The Controller provides general written authorisation for Renvia to engage the sub-processors listed on our Subprocessors page. Renvia will give at least 30 days' notice of any intended addition or replacement and allow the Controller to object on reasonable data-protection grounds.
7. International transfers
Personal Data is stored in the United Kingdom and/or European Economic Area. Where any onward transfer is strictly necessary, Renvia relies on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a Transfer Impact Assessment.
8. Audit
Renvia will make available to the Controller all information necessary to demonstrate compliance with this DPA, including our latest DSP Toolkit submission, penetration test summaries and DCB0129 clinical safety artefacts, and will contribute to Controller-led audits on reasonable notice.
9. Liability & governing law
Liability under this DPA is subject to the limitations set out in the Master Services Agreement. This DPA is governed by the laws of England and Wales.
10. Executing the DPA
To countersign a copy of this DPA on your organisation's letterhead, contact privacy@renvia.health and we will issue a signed PDF within five working days.