Movari — Data Processing Agreement
Version: 2026-07-23 Effective date: 23 July 2026 Status: FINAL — reviewed and approved by qualified UK legal counsel and in force. Supersedes version 2026-06-01.
1. Background and purpose
1.1 This Data Processing Agreement ("DPA") is entered into between:
-
Movari Ltd, a company incorporated in England and Wales with company number 17196208 and registered office at 8 Greenwood Court, Greenwood Mount, Leeds, LS6 4LU (the "Processor", "Movari"); and
-
the Customer that accepts the Movari Terms of Service (the "Controller", "you").
1.2 This DPA is incorporated into and forms part of the Movari Terms of Service ("Terms") between Movari and the Customer. In the event of conflict between this DPA and the Terms in relation to the processing of personal data, this DPA prevails.
1.3 This DPA implements Article 28 of the UK GDPR and gives effect to the relevant requirements of the Data Protection Act 2018 ("DPA 2018").
1.4 In this DPA, "UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as supplemented by the DPA 2018. Terms not otherwise defined in this DPA have the meanings given in the UK GDPR.
2. Roles of the parties
2.1 The parties acknowledge and agree that:
(a) in respect of personal data relating to patients of the Controller (and any other natural persons whose data the Controller submits to the Service), the Controller is the data controller and Movari is the data processor;
(b) Movari acts as independent controller in respect of personal data of the Controller's own staff users (account-administration data, sign-in logs, audit logs of administrative actions, billing data for the Movari subscription, and similar data that Movari processes to operate the Movari business). Movari's processing in that capacity is governed by the Movari Privacy Notice, not by this DPA.
2.2 The Controller warrants that:
(a) it has a lawful basis under the UK GDPR for collecting and processing the personal data it submits to the Service, including any special-category data;
(b) where required, it has provided notice to, and (where relevant) obtained valid consent from, the relevant data subjects;
(c) its instructions to Movari (including any instructions inherent in its use of the Service) comply with the UK GDPR, the DPA 2018 and any other applicable laws.
3. Subject matter, duration, nature and purpose of processing
3.1 Subject matter. Movari processes personal data on the Controller's behalf as part of the supply of the Movari practice-management Service.
3.2 Duration. Movari processes personal data for the duration of the Controller's subscription to the Service, plus the holding period and deletion timelines set out in this DPA.
3.3 Nature of the processing. Storage; transmission; display; search; structured editing; backup; encryption; access logging; audit logging; export; deletion. Movari also performs limited manual normalisation of bulk patient-data uploads at the Controller's request as set out in clause 4.5 (Bulk upload).
3.4 Purpose of the processing. Provision of the Service to the Controller, including:
(a) clinical record-keeping in SOAP format;
(b) rehabilitation-plan creation and patient-facing read-only delivery via magic link;
(c) appointment booking and attendance tracking;
(d) billing-ledger tracking and invoice generation;
(e) referral logging;
(f) document storage attached to a patient record;
(g) where the Controller connects a messaging channel, a unified messaging inbox (WhatsApp, Instagram, Facebook Messenger) for receiving and replying to messages from the Controller's contacts, including deterministic automatic replies the Controller configures;
(h) related security, audit and account-management functions.
3.5 Categories of personal data. The personal data processed includes:
(a) identification and contact data of patients: name, date of birth, address, telephone number, email address, friendly patient identifier;
(b) health data (special-category data under Article 9 UK GDPR): SOAP clinical notes (subjective, objective, assessment, plan); diagnoses; outcome-measure scores (e.g. VAS, DASH, Oxford Knee, Oxford Hip); rehabilitation plan content; adherence logs; clinical files (X-rays, MRI images, posture photographs, clinician-uploaded documents); referral letters and discharge summaries;
(c) financial data of patients: charges, payments, refunds, invoices, outstanding balance entries in the billing ledger;
(d) appointment data: dates, times, durations, locations, attendance status, cancellation history;
(e) practitioner-user data of the Controller's own staff users: name, role, professional registration number, email, sign-in events, MFA factor metadata (but not the underlying secret), audit-log entries of clinical actions;
(f) referral-contact data: names, contact details of GPs, specialists and other referrers logged by the Controller;
(g) messaging / inbox data: where the Controller connects a WhatsApp, Instagram or Facebook Messenger channel — the content of messages exchanged with the Controller's contacts, the contact's channel identifier (e.g. phone number or account handle) and display name, references to media the contact sends (identifiers and file type only, not the media itself), and delivery status. This category may include personal data of persons who are not patients (see 3.6(d)). Message content is not subject to automated analysis or AI processing.
3.6 Categories of data subjects.
(a) patients of the Controller (the primary category);
(b) staff users of the Controller (practitioners and any additional users granted access to the Controller's workspace);
(c) third-party referrers logged by the Controller in the rolodex of referral contacts;
(d) prospective patients and other persons who contact the Controller through a connected messaging channel (WhatsApp, Instagram or Facebook Messenger), including enquirers who never become patients.
3.7 Obligations and rights of the Controller. The Controller's obligations and rights are those set out in this DPA, in the Terms, and in the UK GDPR and DPA 2018, including the obligation to ensure a lawful basis for processing, to respond to data-subject rights requests for which it remains responsible as controller, and to maintain its own records of processing activity.
4. Processor obligations (UK GDPR Art. 28(3))
4.1 Documented instructions — Art. 28(3)(a)
(a) Movari will process personal data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do so by UK law (in which case Movari will inform the Controller of that legal requirement before processing, unless prohibited by law from doing so on important grounds of public interest).
(b) The Controller's documented instructions to Movari consist of:
(i) the Terms;
(ii) this DPA;
(iii) the configuration and functions of the Service as used by the Controller;
(iv) any further written instructions the Controller gives Movari (including by email to privacy@movariapp.com), subject to clause 4.1(c) below.
(c) If Movari considers that an instruction infringes the UK GDPR, the DPA 2018 or any other applicable data-protection law, it will inform the Controller without undue delay and may suspend performance of the instruction pending resolution.
4.2 Confidentiality — Art. 28(3)(b)
(a) Movari will ensure that all personnel authorised to process the Controller's personal data have committed themselves to confidentiality (or are under an appropriate statutory obligation of confidentiality), and that access is restricted to those personnel who need it to provide, secure or support the Service.
(b) This obligation extends to employees, contractors, agency workers, and any other natural persons acting on Movari's behalf.
4.3 Security of processing — Art. 28(3)(c) and Art. 32
(a) Movari implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include:
(i) Encryption in transit (TLS 1.2 or higher) and encryption at rest (AES-256 or equivalent) for all personal data;
(ii) Row-level access controls at the database layer so that each Controller's data is isolated and accessible only by authorised users of that Controller's workspace;
(iii) Mandatory multi-factor authentication ("MFA") for all practitioner users of the Service. MFA is a contractual security requirement and cannot be disabled or waived. Without MFA the user cannot access the main application;
(iv) Append-only audit logging of clinically significant actions (patient creation, note creation and lock, amendment and addendum, magic-link grant or rotation, invoice lifecycle events, document upload, MFA enrolment and unenrolment) retained for the duration of the Controller's subscription;
(v) Signed, short-lived URLs for access to uploaded clinical files, with no permanent public URLs;
(vi) Defence-in-depth controls including application-level patient-ownership checks performed independently of, and in addition to, database row-level security;
(vii) Restricted administrative access for Movari personnel, limited to the minimum number of authorised individuals, with logging of administrative actions;
(viii) Daily encrypted backups of the database, with documented restore procedures tested at least annually;
(ix) Vulnerability management including patching of dependencies and base infrastructure on a defined cadence;
(x) Personnel screening for Movari staff with access to production systems, and security training appropriate to role.
(b) Movari may update these measures from time to time to reflect changes in the threat landscape or technical practice, provided the level of protection is not materially reduced. A current description is made available on request.
4.4 Sub-processors — Art. 28(2) and 28(4)
(a) The Controller gives general authorisation for Movari to engage sub-processors for the purpose of providing the Service. Movari will impose data-protection obligations on each sub-processor that are no less protective than those set out in this DPA, by way of a written contract.
(b) The current list of sub-processors is made available on request and includes (without limitation):
(i) Supabase / Supabase Inc. — hosted database (PostgreSQL), authentication (GoTrue), and object storage (S3-compatible). UK-region hosting where elected by Movari. Used to store all clinical, billing and account data.
(ii) Vercel Inc. — application hosting and edge delivery of the Service.
(iii) Resend — transactional email delivery (e.g. patient access magic-link emails, password-reset emails, MFA notifications).
(iv) Stripe — payment processing for the Movari subscription itself (and, from version 2 onwards, for physio-to-patient session payments via Stripe Connect).
(v) Telnyx — telephony for the call-management feature (inbound UK numbers, call recording); processes the caller's phone number and voicemail audio.
(vi) Microsoft Azure (UK South) — voicemail call-management AI: speech-to-text (Azure AI Speech) and structured summarisation (Azure OpenAI), processed and stored in the United Kingdom (uksouth).
(vii) Meta Platforms — transport of messages on WhatsApp, Instagram and Facebook Messenger (via the Meta Graph API) for the messaging-inbox feature, where the Controller connects a channel; processes the contact's channel identifier and display name, message content, and media references. Meta assets are configured for UK/EU processing where Meta offers it, and transfers are subject to a UK transfer mechanism.
(c) Movari will give the Controller at least 30 days' prior written notice (which may be by email or by an update to the published sub-processor list with notification) of any intended addition or replacement of a sub-processor. The Controller may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the Terms with respect to the affected Service on written notice; no refund is payable except for any fees prepaid in respect of Service not yet provided.
(d) Movari remains fully liable to the Controller for the acts and omissions of its sub-processors in respect of their performance of the data-protection obligations imposed by this DPA.
4.5 Bulk-upload onboarding — Movari-specific instructions
(a) The Service supports an onboarding workflow in which the Controller may upload bulk patient-data files in any reasonable format (paper-scanned PDFs, exports from other systems, spreadsheets, etc.) via the Service.
(b) The Controller's act of uploading such files constitutes the Controller's documented instruction to Movari to import the contained data into the Controller's Movari workspace.
(c) Movari will normalise and transcribe uploaded data manually during the initial onboarding phase, where the file format requires it. This work is performed by Movari personnel bound by the confidentiality obligations in clause 4.2.
(d) The original uploaded files are retained for up to 90 days post-import for verification purposes (so that errors in transcription can be checked against the source). After 90 days they are securely deleted from Movari's storage, leaving only the structured data within the Controller's workspace.
(e) The Controller acknowledges that this is a manual workflow and that, while Movari takes reasonable care, the Controller remains responsible for reviewing imported records for accuracy before relying on them clinically. The Service surfaces incomplete-record warnings (e.g. missing date of birth) that the Controller should resolve.
4.6 Assistance with data-subject rights — Art. 28(3)(e)
(a) Taking into account the nature of the processing, Movari will assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller's obligation to respond to requests from data subjects exercising their rights under Articles 15 to 22 of the UK GDPR (right of access, rectification, erasure, restriction, data portability, objection, and rights related to automated decision-making).
(b) Self-service tooling. The Service provides the Controller with:
(i) a per-patient data export (PDF of the full clinical record plus a zip of attachments) accessible from within the patient record, which can be used to satisfy Subject Access Requests and data-portability requests;
(ii) a patient archive function which removes the patient from operational view (full deletion is not provided through self-service because clinical records are subject to statutory retention — see clause 7 below);
(iii) audit-log visibility within the Service to support evidencing of processing activity.
(c) Provider assistance. Where the Controller requires assistance beyond the self-service tooling, Movari will provide reasonable assistance at no charge, except for unreasonable, repetitive or manifestly unfounded requests for which Movari may charge its reasonable costs.
(d) The Controller commits, and the Service is designed to enable the Controller, to respond to Subject Access Requests within the 30-day period required by Article 12(3) of the UK GDPR. Movari will provide any reasonable assistance required to meet that timeline.
(e) Movari will not respond directly to data subjects in respect of their rights against the Controller, except to direct them to contact the Controller.
4.7 Assistance with security, breach notification and DPIAs — Art. 28(3)(f)
(a) Taking into account the nature of the processing and the information available to Movari, Movari will assist the Controller in:
(i) ensuring compliance with the obligations under Articles 32 to 36 of the UK GDPR, including the security of processing, the notification of personal-data breaches to the supervisory authority and to data subjects, and data-protection impact assessments and prior consultation;
(ii) providing reasonable information about Movari's security measures and sub-processors to support the Controller's own risk assessment.
(b) Breach notification. Movari will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal-data breach affecting personal data processed under this DPA. The notification will include, to the extent known at the time:
(i) the nature of the breach, including categories and approximate numbers of data subjects and data records concerned;
(ii) the likely consequences;
(iii) measures taken or proposed to address the breach and to mitigate possible adverse effects;
(iv) the name and contact details of a contact point at Movari from whom more information can be obtained.
Movari will update the Controller as more information becomes available. The Controller is responsible for any notification to the Information Commissioner's Office and to affected data subjects as required by the UK GDPR; Movari will provide reasonable assistance with such notifications.
4.8 Return or deletion of data — Art. 28(3)(g)
(a) At the choice of the Controller, on termination or expiry of the Terms, Movari will:
(i) return the personal data to the Controller in a structured, commonly used and machine-readable format (the Service provides per-patient PDF + attachment zip export, and on request an aggregate workspace export); and/or
(ii) delete all existing copies of the personal data,
unless retention is required by UK law.
(b) Account-closure flow. When the Controller triggers account closure via the Service:
(i) the Controller is provided with the full export described above;
(ii) all patients and rehabilitation plans in the workspace are archived so that patient magic-link access ceases immediately;
(iii) a 30-day holding period runs, during which the Controller can re-open the account or download a fresh export;
(iv) at the end of the holding period, a daily scheduled job purges (A) all storage objects under the Controller's path in the patient-documents bucket and then (B) every database row owned by the Controller in dependency order, ending with the deletion of the user record and cascading deletion of authentication artefacts.
(c) The Controller acknowledges that deletion at the end of the 30-day holding period is irreversible.
(d) Backups containing the deleted personal data are overwritten in accordance with Movari's backup-rotation cycle and are not subject to selective deletion. While they remain on backup media they continue to be subject to the security measures in clause 4.3.
4.9 Audit — Art. 28(3)(h)
(a) Movari will make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 UK GDPR.
(b) Movari will allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, on reasonable prior written notice (and in any event not less than 30 days' notice except in the case of a confirmed personal-data breach affecting the Controller's data).
(c) Audits are subject to the following conditions, which the parties agree are reasonable:
(i) no more than once per calendar year, except where required by a supervisory authority or following a personal-data breach;
(ii) conducted during normal business hours and in a way that does not unreasonably disrupt Movari's business or the security of other Controllers' data;
(iii) any auditor not employed by the Controller must enter into a written confidentiality agreement with Movari;
(iv) the auditor must not have access to any other Movari customer's data or to commercially sensitive information unrelated to the Controller;
(v) the Controller bears its own audit costs and reimburses Movari's reasonable costs for personnel time and access provision at standard professional rates.
(d) Movari may, in its reasonable discretion, satisfy its audit obligations by making available independent third-party audit reports (such as SOC 2 Type II, ISO 27001, or equivalent) where they are available and reasonably address the Controller's audit objectives.
5. International transfers
5.1 Movari and its sub-processors store personal data within the United Kingdom and the European Economic Area where reasonably practicable. The Controller's primary data store is hosted in a UK region of the Supabase platform unless otherwise agreed in writing.
5.2 Where Movari or a sub-processor transfers personal data to a country outside the UK that is not the subject of an adequacy regulation under the DPA 2018, Movari will put in place an appropriate transfer mechanism, which may include:
(a) the UK International Data Transfer Agreement (IDTA) issued by the Information Commissioner under section 119A of the DPA 2018; or
(b) the EU Standard Contractual Clauses as supplemented by the UK Addendum to the EU SCCs issued by the Information Commissioner; or
(c) such other transfer mechanism as is lawful under the UK GDPR.
5.3 The Controller authorises such transfers, subject to the transfer mechanism being in place. The Controller agrees to enter into the IDTA or UK Addendum where required to give effect to such transfers between the Controller (as data exporter) and a sub-processor (as data importer), and grants Movari a limited power of attorney to execute such transfer agreements on the Controller's behalf with sub-processors where reasonably necessary.
6. Retention by the Controller
6.1 The Controller is the data controller of clinical records held in the Service and is responsible for compliance with all clinical-record retention obligations applicable to its practice.
6.2 In the United Kingdom this typically requires retention of adult patient records for at least eight (8) years from the date of last treatment, and longer for paediatric patients (typically until the patient's 25th or 26th birthday). Specific requirements vary by profession, by the patient's age, and by the nature of the care given. The Controller is responsible for taking its own professional and legal advice on the applicable period.
6.3 The Service is designed to retain clinical records for as long as the Controller maintains a paid subscription. It is not designed as a long-term archival system after account closure. On account closure the Controller must download and retain the export referred to in clause 4.8 to meet its own retention obligations beyond the 30-day holding period.
6.4 Movari will not delete personal data from an active workspace except (a) on the Controller's documented instruction (including the archive and account-closure flows), (b) as required by law, or (c) as set out in clause 4.5(d) (deletion of original bulk-upload files 90 days post-import).
7. Term and termination
7.1 This DPA takes effect on the date the Controller accepts the Terms and continues for as long as Movari processes personal data on behalf of the Controller.
7.2 Clauses 4.8 (return or deletion), 4.9 (audit, in respect of the relevant retention period), 8 (liability), and 9 (general) survive termination of this DPA.
8. Liability
8.1 The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in clause 13 (Limitation of liability) of the Terms, which apply to this DPA as if set out in full here.
8.2 Nothing in this DPA limits or excludes the rights of data subjects under the UK GDPR.
9. General
9.1 If there is any conflict between this DPA and the Terms in relation to the processing of personal data, this DPA prevails.
9.2 If there is any conflict between this DPA and the UK GDPR or DPA 2018, the UK GDPR or DPA 2018 prevails.
9.3 Notices about data-protection matters should be sent to privacy@movariapp.com.
9.4 This DPA is governed by the laws of England and Wales and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
Annex 1 — Summary of processing
| Item | Detail |
|---|---|
| Controller | The Movari Customer accepting the Terms |
| Processor | Movari Ltd, 8 Greenwood Court, Greenwood Mount, Leeds, LS6 4LU, Company No. 17196208 |
| Subject matter | Provision of the Movari practice-management Service |
| Duration | Term of the Customer's subscription + retention and deletion timelines in clauses 4.5(d) and 4.8 |
| Nature | Storage, transmission, display, search, structured editing, backup, encryption, access logging, audit logging, export, deletion, limited manual normalisation of bulk uploads |
| Purpose | Practice management, clinical record-keeping, rehabilitation-plan delivery, appointments, billing-ledger, referral logging, document storage, messaging-inbox (WhatsApp/Instagram/Messenger) |
| Categories of personal data | Identification and contact data; health data (Art. 9 special-category); financial data; appointment data; practitioner-user data; referral-contact data; messaging / inbox data (message content + contact identifiers, where a channel is connected) |
| Categories of data subjects | Patients of the Controller; staff users of the Controller; third-party referrers logged by the Controller; prospective patients and other persons who message the Controller on a connected channel |
| Special category processing | Yes — health data under Article 9 UK GDPR |
| International transfers | UK / EEA primary storage; out-of-UK transfers only with IDTA, UK Addendum to EU SCCs, or other lawful mechanism |
Annex 2 — Sub-processors (initial list)
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Hosted PostgreSQL database, authentication, S3-compatible object storage for clinical files | UK region (primary) |
| Vercel Inc. | Application hosting and edge delivery | EU / UK regions where available |
| Resend | Transactional email delivery | EU / US (subject to UK transfer mechanism) |
| Stripe | Payment processing for the Movari subscription (and, from version 2, physio-to-patient session payments via Stripe Connect) | UK / IE |
| Telnyx | Telephony for call management — inbound UK numbers, call recording (caller phone number + voicemail audio) | UK number; EU/US carriage under a UK transfer mechanism |
| Microsoft Azure (UK South) | Voicemail AI — speech-to-text (Azure AI Speech) + structured summarisation (Azure OpenAI gpt-4o) | United Kingdom (uksouth) — processed and stored in the UK |
| Meta Platforms (WhatsApp, Instagram, Messenger) | Message transport for the messaging-inbox feature (Meta Graph API) — contact identifier, display name, message content, media references | Meta platform infrastructure; UK/EU processing where offered, under a UK transfer mechanism |
Movari maintains a current sub-processor list and notifies the Controller of changes in accordance with clause 4.4(c).
Annex 3 — Security measures (summary)
A summary of the technical and organisational measures referred to in clause 4.3:
- Encryption. TLS 1.2+ in transit; AES-256 (or equivalent) at rest for database and storage.
- Access control. Row-level security at the database layer scoping every clinical and billing table to the owning practitioner; application-level patient-ownership checks as defence-in-depth.
- Authentication. Email + password with mandatory time-based one-time-password (TOTP) MFA for all practitioner accounts. MFA cannot be disabled. AAL2 required for sensitive actions including password change.
- Audit logging. Append-only
audit_logtable written via SECURITY DEFINER RPC; clinically significant events recorded; visible to the Controller within the Service. - File storage. Private object-storage bucket; signed, short-lived URLs only; no permanent public links; per-physio, per-patient path scoping.
- Personnel. Confidentiality obligations; minimum necessary access to production; security training appropriate to role.
- Backups. Daily encrypted backups; documented restore procedures.
- Account closure and deletion. Controller-triggered closure with 30-day holding period followed by storage-first, dependency-ordered deletion across the database, ending with cascading deletion of authentication artefacts.
- Patient PWA. Read-only access via tokenless
/pURL backed by an HttpOnly cookie set during a single redeem round-trip; magic-link tokens are rotated on each grant and validated via SECURITY DEFINER RPC. - Append-only clinical record. Clinical notes, once locked, become immutable; amendments and addendums are append-only and full history is preserved.
End of Data Processing Agreement, version 2026-07-23.